MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f1f18b0a7efd6702ce47f9bea620165785050d55074d6ae27e6a6ff4322f6ad3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | f1f18b0a7efd6702ce47f9bea620165785050d55074d6ae27e6a6ff4322f6ad3 |
|---|---|
| SHA3-384 hash: | 5c7ebb5c05d61f737bae5f0d8cabbdd573c715dd610e0d5ad86645398af91da80d3698c568fef82b55ec3f2f68911724 |
| SHA1 hash: | dd4485960723c552b40decf3592d92c29b22c2fe |
| MD5 hash: | 788dbf576e0a2674990aca2e9360b270 |
| humanhash: | island-arkansas-bravo-comet |
| File name: | hesaphareketi000,pdf.xz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 339'263 bytes |
| First seen: | 2020-08-03 14:15:50 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:xjBgVFnQnwBYQSRS+ZEaLmitEVuGVMM7Z4GUFv7qv93iNKNajPbQIqxB:xd8FnQwaQp7GmiiVluMq5Fv7qANKNaje |
| TLSH | 4574230CE6C7355AFEF5F7483E6F5799131E7BB0062EB3963701486059093B64A8361E |
| Reporter | |
| Tags: | AgentTesla geo TUR xz |
abuse_ch
Malspam distributing AgentTesla:HELO: garantibbva.com.tr
Sending IP: 155.94.136.61
From: ekstre@garantibbva.com.tr
Subject: Hesap hareketleriniz
Attachment: hesaphareketi000,pdf.xz (contains "hesaphareketi000,pdf.exe")
AgentTesla SMTP exfil server:
mail.slbdc-lk.org:587
AgentTesla SMTP exfil email address:
finance@slbdc-lk.org
Intelligence
File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
PUA.Win.Packer.ProtectSharewar-2
PUA.Win.Packer.ProtectSharewar-3
Win.Virus.Sality
Win.Trojan.VBGeneric-6735885-0
Win.Virus.Sality-6747602-0
Win.Malware.Swisyn-6803865-0
Win.Malware.Swisyn-7610491-0
Win.Malware.Swisyn-7610494-0
Win.Trojan.Kazy-304
Sanesecurity.Malware.26176.ZipHeur.BadExt.UNOFFICIAL
PUA.Win.Packer.ProtectSharewar-3
Win.Virus.Sality
Win.Trojan.VBGeneric-6735885-0
Win.Virus.Sality-6747602-0
Win.Malware.Swisyn-6803865-0
Win.Malware.Swisyn-7610491-0
Win.Malware.Swisyn-7610494-0
Win.Trojan.Kazy-304
Sanesecurity.Malware.26176.ZipHeur.BadExt.UNOFFICIAL
Threat name:
Win32.Trojan.Swisyn
Status:
Malicious
First seen:
2020-08-03 14:17:05 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.