MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8b9ae0dc75839f4c6ed2d4b1d0afff247677e5c21eee65e932be3bd1cc5161b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e8b9ae0dc75839f4c6ed2d4b1d0afff247677e5c21eee65e932be3bd1cc5161b
SHA3-384 hash: 7e97c51452786cf077b5c9a6e6e58bf9f994fbb413153aed665858267d2605796cf74b15c798a5f19b391d8eb4d8c784
SHA1 hash: 2ab4a0749f25110be22bc811cb4951a1ee25883d
MD5 hash: 08f3d0e8a97c47ac682638c5431a4d85
humanhash: nuts-grey-lake-delta
File name:Halkbank_Ekstre_20200405_075748_550793.pdf.r00
Download: download sample
Signature AgentTesla
File size:1'217'079 bytes
First seen:2020-05-04 21:22:00 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:S+/7zMjAnjo6oe5EjBzOwUAyixgn2tYlwpmpKRd7G7rWD5GYwXJeRhjo:NXMMnM6oUEjBawN9xg2tOyd7qWD5GLT
TLSH A1453314A58F73253F743D2E01A7665F5CB43ECB0E1942FED56EEA424E8A31A82CCE15
Reporter abuse_ch
Tags:AgentTesla geo Halkbank r00 TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.nesbil.net
Sending IP: 5.180.187.171
From: HALKBANK.E-EKSTRE@halkbank.com.tr
Subject: T.HALK BANKASI A.Ş. 03.05.2020 Hesap Ekstresi
Attachment: Halkbank_Ekstre_20200405_075748_550793.pdf.r00 (contains "Halkbank_Ekstre_20200405_075748_550793.pdf.exe")

AgentTesla SMTP exfil server:
mail.newtorres.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-05 04:03:28 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 e8b9ae0dc75839f4c6ed2d4b1d0afff247677e5c21eee65e932be3bd1cc5161b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments