MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54f574816f91352e7c3375db7c486d9b6a6b627cc3d37a5206e65a2bd29732d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 4 Yara Comments

SHA256 hash: 54f574816f91352e7c3375db7c486d9b6a6b627cc3d37a5206e65a2bd29732d8
SHA3-384 hash: 0d05d6fa3ac943b606f90350592e9c1db61c3dbacb8b6105e166555d8015ca28b8642d6190c6c5727f6e2a9dcaaf53db
SHA1 hash: 488f2266dc2fa047746f397543ed84975832879a
MD5 hash: eb15b299410b46d69417f77963e290c4
humanhash: pluto-cat-coffee-emma
File name:SWIFT EUR 21924,74 20200629145649.gz
Download: download sample
Signature AgentTesla
File size:377'994 bytes
First seen:2020-06-30 12:48:58 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:pC2ZsHN2FPI5QVCok9232lMxcE/QBwIDKX1DvyFm7/lEu51XZI7FrTs0IA:oXHN21Iok2QMx7/QBwIWX12Fm7/D5FKb
TLSH 4284231E6F98F262788368D400B89D7FAB445F08EB1085792C77D88A0E57BCBE54F066
Reporter @abuse_ch
Tags:AgentTesla gz

Malspam distributing AgentTesla:

Sending IP:
From: Finance <>
Subject: FW: SWIFT payment EUR 21924,74 20200629145649
Attachment: SWIFT EUR 21924,74 20200629145649.gz (contains "SWIFT EUR 21924,74 20200629145649.exe")

AgentTesla SMTP exfil server:

AgentTesla SMTP exfil email address:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 24
Origin country US US
ClamAV No detection
CERT.PL MWDB Detection:n/a
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 12:50:05 UTC
AV detection:14 of 31 (45.16%)
Threat level:   5/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 11.48%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



gz 54f574816f91352e7c3375db7c486d9b6a6b627cc3d37a5206e65a2bd29732d8

(this sample)

Delivery method
Distributed via e-mail attachment