MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbf0650bdf2730676d4c93010548dbcf32f77cdf1a2dd223a417af573b3d29b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cbf0650bdf2730676d4c93010548dbcf32f77cdf1a2dd223a417af573b3d29b1
SHA3-384 hash: 502f8106909b2c3b4a537c6b2c01932637f66038d3542944cc7ae2660c6e87d43a872ab59986c00dc7ee50a7770f4646
SHA1 hash: 643ab6c6950ffc1a7aa81440a483e2169cf59fb6
MD5 hash: 30b6bf52114232d46582da4444ee7cae
humanhash: wyoming-vegan-nuts-stream
File name:Halkbank_Ekstre_202004289_121858_22631.z
Download: download sample
Signature AgentTesla
File size:1'121'754 bytes
First seen:2020-04-30 07:38:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:BXta0if2pSdJYgw0Df7gLXa13isg6NZ8PSmkcC9L/HIgYmCYTvadUx:i0ifVFbc7USsgoZwcwWiUx
TLSH BF3523D1DC3F34A3B5B8B672B454A06578303A22CA993B4D1937ED2D1A246DFDF24A12
Reporter abuse_ch
Tags:AgentTesla geo TUR z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: halkbank.com.tr
Sending IP: 156.96.58.98
From: halkbank.e-ekstre@halkbank.com.tr
Subject: T.HALK BANKASI A.S.20.04.2020 - 29.04.2020 Hesap Ekstresi
Attachment: Halkbank_Ekstre_202004289_121858_22631.z (contains "Halkbank_Ekstre_202004289_121858_22631.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-30 08:36:12 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip cbf0650bdf2730676d4c93010548dbcf32f77cdf1a2dd223a417af573b3d29b1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments