MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0abe55ab21303fd427664eb0dadb8126a64fa90e529ec5447776899ecbffc8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f0abe55ab21303fd427664eb0dadb8126a64fa90e529ec5447776899ecbffc8e
SHA3-384 hash: 64d4f5829205889ea1929c62266ddcd695aece1ef4088407729bdc405ce49ad74823a8ca8c70badb8552f2fe50197656
SHA1 hash: 8dbc4c579e69e93676e4249154f10363048f0aea
MD5 hash: 880a80d1a0ef91c7bddb908f565d2803
humanhash: robin-pluto-bacon-timing
File name:SWIFT_3390024892_USD_44,986.84.iso
Download: download sample
Signature AgentTesla
File size:745'472 bytes
First seen:2020-06-01 19:46:31 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:GxUoYV5+pgxmx5xoxJsYuZ25qSQXZbFe34xzooAu0Yed3QN6M49E2pvqgiy:GqoYV5oAEoxWYu0qSQfeo1oK
TLSH FCF48C9C762072EFC85BC4729EA81C64FA51747B831B4613A42B15EDEE1C88BCF255F2
Reporter abuse_ch
Tags:AgentTesla HSBC iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: xinhgai.site
Sending IP: 150.95.112.115
From: Anna Weidmann - Account dept HSBC<treybd@gmail.com>
Subject: Payment Advice Note dt. 01.06.2020
Attachment: SWIFT_3390024892_USD_44,986.84.iso (contains "SWIFT_3390024892_USD_44,986.84.exe")

AgentTesla SMTP exfil server:
mail.suncurepelletmill.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-01 20:36:28 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso f0abe55ab21303fd427664eb0dadb8126a64fa90e529ec5447776899ecbffc8e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments