MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efca87946f7d8ed91396af70c51417bb8e64b7d4945dd6b719ac3e9208ee60a3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: efca87946f7d8ed91396af70c51417bb8e64b7d4945dd6b719ac3e9208ee60a3
SHA3-384 hash: 94988a42198ea39b09cb7e16150ef377b29f88cdd34d913db71a2bdc52e858d3cda41a9656287f66dd66c9c4605b6957
SHA1 hash: 7785f662a45a066c58dde8fa23cd454bd57d9781
MD5 hash: 99f49dbdf398f322a16959a99f9f68a0
humanhash: kitten-coffee-carolina-eighteen
File name:Akbank Hesap Özetiniz.pdf.r00
Download: download sample
Signature AgentTesla
File size:406'971 bytes
First seen:2020-05-11 14:51:27 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:55hWFC8/hzK5kPE8MFxnpcz+gQZIKbrxMCMkIm:jhWsaK5kPtMFRpj3ZpGI
TLSH 77842393ABA018AC50359B7B8B293F1B890F4FD8DFF41E5B27389AF654043A725039C5
Reporter abuse_ch
Tags:AgentTesla Akbank geo r00 TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: correo.sentidocomun.es
Sending IP: 54.217.206.198
From: AKBANK <hizmet@bilgi.akbank.com>
Subject: Akbank Hesap Özetiniz (Ref:20852932368)
Attachment: Akbank Hesap Özetiniz.pdf.r00 (contains "Akbank Hesap Özetiniz.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 15:37:30 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 efca87946f7d8ed91396af70c51417bb8e64b7d4945dd6b719ac3e9208ee60a3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments