MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f6edcf7da7ee089f81232b45625a01aabc1699b4f0783b0d495a32fd210ea03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8f6edcf7da7ee089f81232b45625a01aabc1699b4f0783b0d495a32fd210ea03
SHA3-384 hash: 1caa23d3239676e1d36ad38554fac803cdf2911a32f6b8134927059d4532eb55a508db8c7a0a3534a7deacbbe2ca19b3
SHA1 hash: 0c21379526a1cbfeb1758692d08b7ba2e537c243
MD5 hash: c9caeb5b8a273ec44e998946a29596a9
humanhash: april-orange-twenty-undress
File name:Swift MT103 EUR 5000 PDF.gz
Download: download sample
Signature AgentTesla
File size:469'192 bytes
First seen:2020-06-23 06:12:57 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:NnY+p5e0NWq6438yGiDXv1xu0oZIlpK1wU:CUkoDXtxuXIl8mU
TLSH D0A4230F73359CFD80A2262F2783AE75F94023A856077E3D3E6273458959BB9D246B4C
Reporter abuse_ch
Tags:AgentTesla gz HSBC


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.701.semiopraxi.casa
Sending IP: 134.122.56.15
From: HSBC Advising Service <AdvicesMY@sc.com>
Subject: Payment Advice - Ref: HSBC99002992/01062020
Attachment: Swift MT103 EUR 5000 PDF.gz (contains "Swift MT103 EUR 5000 PDF.exe")

AgentTesla SMTP exfil server:
mail.salkic.co.ba:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-23 06:14:04 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 8f6edcf7da7ee089f81232b45625a01aabc1699b4f0783b0d495a32fd210ea03

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments