MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 947f9327cc95d27e945b43aa40dbfdd9e8fda5e793914ea1df4d0ab1628749ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 947f9327cc95d27e945b43aa40dbfdd9e8fda5e793914ea1df4d0ab1628749ce
SHA3-384 hash: 2126ee06dc818740b7ae72147f0e743b93bc839c95d8c4a974541ce1572ffac512cd0627de443da78b02dfb58e62d3d9
SHA1 hash: 94ed25e01629e81faa32cf7891f1e5372ffc2865
MD5 hash: d8a23d22c656df957a0d3b9185229ef2
humanhash: oxygen-network-robert-football
File name:PAYMENT SLIP COPY.rar
Download: download sample
Signature AgentTesla
File size:290'019 bytes
First seen:2020-05-12 08:40:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:96NlxHCG/bFpDw6VBOWtgCUlZ173BmBdBvjWIRKqM:AlCGTFx1VTKbz173QBvWxT
TLSH 4B5423841EEDA406DC67B22370811F072CBCEFF56514BA2AB99E84E24429DFCF588613
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.citroenbayi.com
Sending IP: 185.153.221.62
From: Hilton Istanbul Bomonti Hotel <edizhakan@hilton.com>
Subject: SWIFT DOCUMENT
Attachment: PAYMENT SLIP COPY.rar (contains "PAYMENT SLIP COPY.exe")

AgentTesla SMTP exfil server:
mail.yaprakmoda.com:587

AgentTesla SMTP exfil email address:
musteritemsilcisi@yaprakmoda.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-12 19:56:56 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 947f9327cc95d27e945b43aa40dbfdd9e8fda5e793914ea1df4d0ab1628749ce

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments