MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9c62f4e76179e8480f93216a984d8e2d3168d2b2adc604aa5867145e262743ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9c62f4e76179e8480f93216a984d8e2d3168d2b2adc604aa5867145e262743ad
SHA3-384 hash: d7723bb1f08e55c6cc8f54affa901533a8ee329e44a4b7e39f0ccdf8628332f6b0aef1b316e47e47f56d1f464898d2eb
SHA1 hash: ba0a2a703d024a7682770abe3b68eb4e85de8943
MD5 hash: 27467afc8c6b986b5b543433f3993433
humanhash: golf-october-yankee-nevada
File name:SWIFT COPY.z
Download: download sample
Signature AgentTesla
File size:938'154 bytes
First seen:2020-05-13 07:17:41 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 24576:/wyVCOhFXsLq0FGIotVyGqiqKcw/scTkp9:xALq/I+RqBKcw/s7f
TLSH FC153313241EE4626C361822E5415FDEFCA0D4BD255B6050AE1FCBBF7FDDA269E2C214
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: venturasteels.com
Sending IP: 156.96.157.101
From: BANK<pune@venturasteels.com>
Subject: BANK
Attachment: SWIFT COPY.z (contains "SWIFT COPY.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 07:36:58 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 9c62f4e76179e8480f93216a984d8e2d3168d2b2adc604aa5867145e262743ad

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments