MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfcc74e453e4e01a16d864bad85747e1ed62ef3a250bd7434ee95745ac88112a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bfcc74e453e4e01a16d864bad85747e1ed62ef3a250bd7434ee95745ac88112a
SHA3-384 hash: 29aa6915823c072a9dad513a3d0637464a202e4e8096dfbdade41fbc17741dd96dd9a0d3cb16f91491c60037b96c4c57
SHA1 hash: cb214de53fc69f8d811bb4f63b91060e999e2611
MD5 hash: acd2f3a95d63bb6f082ec595dd0f98aa
humanhash: pennsylvania-echo-timing-oxygen
File name:TT- Swift Copy 2.zip
Download: download sample
Signature AgentTesla
File size:1'077'499 bytes
First seen:2020-06-08 12:23:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:jK+p4df1ujbeMpfL6N+Jz3SRIPF9+Zhr0ZcaP:jKv4beQj6qTrF9+jr0SW
TLSH 8535331842CEAB660DC792E756B235AD1BBFF2CAD1C11682375F74A09DA1F0FA05C760
Reporter abuse_ch
Tags:AgentTesla DBS geo SGP zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.edicoes-religiosas.com
Sending IP: 78.46.77.226
From: DBS Bank <info@dbs.com.sg>
Subject: TT- Swift Copy: 471/35/13A-2773 From DBS Bank
Attachment: TT- Swift Copy 2.zip (contains "TT- Swift Copy.exe")

AgentTesla SMTP exfil server:
mail.hotel71.com.bd:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-08 12:25:06 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip bfcc74e453e4e01a16d864bad85747e1ed62ef3a250bd7434ee95745ac88112a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments