MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5fc861269395e4988367ee6859c9961daba9fd6c1aba5f603ddbb4e401e5f60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e5fc861269395e4988367ee6859c9961daba9fd6c1aba5f603ddbb4e401e5f60
SHA3-384 hash: bffa0b43b236198a3dcd12adc693d187abe325b68c0d305a77e75a1a916b74b6db66bfcedbbd5a2701cea14be390af69
SHA1 hash: 88962d893e666ac8ab866b61df08a9964aafd2f5
MD5 hash: 189bc72c6d06a26bbb2048e860e192a7
humanhash: skylark-sink-bacon-florida
File name:Bank swift.z
Download: download sample
Signature AgentTesla
File size:1'023'310 bytes
First seen:2020-05-12 15:54:03 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 24576:zirNStQGXBiA3U3L4GNJaV/krnXIwz8sVrw:zirNS2GXgL4OAmjL8v
TLSH 392533E86124B1B1C481701B6B5D7D46ADCFE52B76A247CC921FC19D01DAEAA30FB63C
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: canfinhomes.com
Sending IP: 156.96.157.101
From: BANK<electroniccity@canfinhomes.com>
Subject: Bank
Attachment: Bank swift.z (contains "Bank swift.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 03:48:30 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z e5fc861269395e4988367ee6859c9961daba9fd6c1aba5f603ddbb4e401e5f60

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments