MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1d48e9189cf9529586c6112df61e7a60de6926b5775aa8650abda95b085693f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1d48e9189cf9529586c6112df61e7a60de6926b5775aa8650abda95b085693f4
SHA3-384 hash: 7a6df5c6ab37664774fa993b17d7e6a683c841ef93c8ef8c682f98e60136889a0ca477d5bc054a987d1f5e3a3a9f2580
SHA1 hash: 12db2655b0659c3c3c7b19918be1933e697c1ccf
MD5 hash: 4465df61a90fc350ff63fbb329252926
humanhash: apart-missouri-shade-london
File name:Halkbank_Ekstre_202004 2020.z
Download: download sample
Signature AgentTesla
File size:375'592 bytes
First seen:2020-05-07 11:00:08 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:8LSuPJnzgg34Z5iC3sXkiHF0AS8CsvtPyQBERpWTx1p7Q4UFVqVpkDSRfERJfyi/:8L5PJnzgviCokil0AS8CYPy2ERpWTxre
TLSH FA84232F0299503EF9085735900CBA05F38BBE7BDB61249DC0CBA649E599EB34FD81A1
Reporter abuse_ch
Tags:AgentTesla geo Halkbank TUR z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.elmasgrafik.com
Sending IP: 185.48.182.122
From: HALKBANK E-EKSTRE <halkbank.e-ekstre@halkbank.com.tr>
Reply-To: noreply@ileti.isbank.com.tr
Subject: İş Bankası-05.05.2020-07.05.202\x0a\x090 -2220-0---252 Numaralı Vadesiz Hesap - TL Özeti.
Attachment: Halkbank_Ekstre_202004 2020.z (contains "Halkbank_Ekstre_202004 2020.exe")

AgentTesla SMTP exfil server:
smtp.ionos.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Noon
Status:
Malicious
First seen:
2020-05-07 11:35:42 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 1d48e9189cf9529586c6112df61e7a60de6926b5775aa8650abda95b085693f4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments