MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6407d65f2d736e32883f38a5d5dd572d02c9535262aade49ee787058e9e09eab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6407d65f2d736e32883f38a5d5dd572d02c9535262aade49ee787058e9e09eab
SHA3-384 hash: 1a325b15ec8d7738dc59ed4c67b153dc6ac31ca4b6abcf2f0738b2b8a17d8db1c76235391c6ec5bc9ed76e995bc50bdb
SHA1 hash: 6708b395983cb43908b623a7822b1cde124abbf6
MD5 hash: 000c262b34647184b42d69bcadeb80d6
humanhash: uranus-hamper-muppet-mango
File name:Account details.gz
Download: download sample
Signature AgentTesla
File size:441'297 bytes
First seen:2020-06-29 06:22:55 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:zgCMxlzuwlXzRvGvNa2krp0Wys6788cozBM0r:zgCM2w5gVor5g78+
TLSH B894236B6F0C7F5384B9418E65D220B9BA175C1D41B5F846BEBC328CA7ACB389235707
Reporter abuse_ch
Tags:AgentTesla gz HSBC


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.616.xianwongleepxc.casa
Sending IP: 64.225.96.94
From: HSBC BANK <noreply@hsbc.co.uk>
Subject: Re: Account details confirmation
Attachment: Account details.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
smtp.mhlogg.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.PonyStealer
Status:
Malicious
First seen:
2020-06-29 06:24:07 UTC
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 6407d65f2d736e32883f38a5d5dd572d02c9535262aade49ee787058e9e09eab

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments