MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b297ef7267a2cb1143bbdeaffd48489afd9a9a7a0ea71f54f1f16b7679e9efab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b297ef7267a2cb1143bbdeaffd48489afd9a9a7a0ea71f54f1f16b7679e9efab
SHA3-384 hash: 6cedbfdb385c30d4f707c7ff0b742a148afad0ec1a41e195f1afef35b9534b263b87dd420e2d4043ccbbb2b7b1247b9d
SHA1 hash: 1097119d99e96a6c079986fdc56399b1cf7f5923
MD5 hash: 6d3a36f36192c21d8996a5c404533a87
humanhash: oregon-video-ink-sixteen
File name:Swift copy.rar
Download: download sample
Signature AgentTesla
File size:431'625 bytes
First seen:2020-06-25 12:54:53 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:hIP2GKNJxha2M3+i4QaNucWshlZyIVvRoBk:h1K2c4fdh70Bk
TLSH 8494230CF8FC60E0E5FB11A1A555AA0B2ED40AD3A1E1B214E798425E2CFDEFD91B44F5
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mesonjulian.com
Sending IP: 45.143.222.124
From: Brian Alex <contacto@mesonjulian.com>
Subject: BANK SWIFT COPY
Attachment: Swift copy.rar (contains "Swift copy.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-06-25 13:37:56 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b297ef7267a2cb1143bbdeaffd48489afd9a9a7a0ea71f54f1f16b7679e9efab

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments