MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43cbfa599af30d7577cb59db8793a90c68d6034d98d2148086f89d3351661ba0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 43cbfa599af30d7577cb59db8793a90c68d6034d98d2148086f89d3351661ba0
SHA3-384 hash: 2e1f89a313986ee9b65b0da37c5587d107391160d24ac71be8bafb6cbae022a1c5154bd7b3351ae61a63fbe26db737fc
SHA1 hash: d8c628d6ac4cc84241e497d620c584f78631bbf9
MD5 hash: c99b8082755e746661e4a16d55d54383
humanhash: edward-mobile-cup-helium
File name:Remittance Advice _0000Swift.img
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2020-08-21 05:15:17 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:tqEp9L5YG8S7EdJkR5Tmj/lDQ2FHS1BXUOklrSnqXFP0a8b29c5APtB+J+S:xn5Y+7P3a/l08SorSnz29c5X
TLSH B0659D62A2E008FEC0662A3F9D1B56749825BD31EF3459762BEDFC484F396813C35297
Reporter cocaman
Tags:AgentTesla img


Avatar
cocaman
Malicious email
From: Account TT <nil@guyana.net.gy>
Received: from mail.sekawan.com (mail.sekawan.com [45.251.72.199])
Date: Fri, 21 Aug 2020 10:23:16 +0700
Subject: RE : REMITTANCE ADVICE
Attachment: Remittance Advice _0000Swift.img

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-21 01:46:09 UTC
File Type:
Binary (Archive)
Extracted files:
70
AV detection:
17 of 47 (36.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 43cbfa599af30d7577cb59db8793a90c68d6034d98d2148086f89d3351661ba0

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments