MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b61b8a3b5f508b283c58dece3970dc22bf17f747135c183bfbb1a3802eae86f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1b61b8a3b5f508b283c58dece3970dc22bf17f747135c183bfbb1a3802eae86f
SHA3-384 hash: 04ae9e138b9815d13936274119f4b917feecd601949700860bcdf88e48f46b3642441230efd346844d806cb3e3fd45bd
SHA1 hash: e01889817c6d738c59065257dcd57c9e3fbda5f3
MD5 hash: a56b8e7e01d30ccfc03bf66b7c2028f3
humanhash: nine-nineteen-sweet-floor
File name:SWIFT.rar
Download: download sample
Signature AgentTesla
File size:378'639 bytes
First seen:2020-09-10 10:23:21 UTC
Last seen:2020-09-11 09:29:28 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:41haoZGNPt47p1DkD+GsuDKHhRemX/EojhGtI43iIhUXw8rFjQSHd2pGSpdAExL2:4rpeiv2+GLDdmPEolGe43iIhUXwgjR20
TLSH C184235196D02FB20F5A4E7D53024791E5C7CA3CABD19A2B5CB11F08B7C892D2D2EE27
Reporter cocaman
Tags:AgentTesla rar


Avatar
cocaman
Malicious email
From: Lychee <lychee@ike.cn>
Received: from ike.cn (unknown [209.58.149.99])
Date: 10 Sep 2020 12:33:28 -0700
Subject: SWIFT
Attachment: SWIFT.rar

Intelligence


File Origin
# of uploads :
3
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DelfInject
Status:
Malicious
First seen:
2020-09-10 09:48:31 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 1b61b8a3b5f508b283c58dece3970dc22bf17f747135c183bfbb1a3802eae86f

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments