MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b78271cf652d50dfd1efc62c73cd6b3656649a7cdce2a4163d8cb8791bd295e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b78271cf652d50dfd1efc62c73cd6b3656649a7cdce2a4163d8cb8791bd295e1
SHA3-384 hash: f276bd10fd5480a2075c1118081bfd6b375ae657a0bb6cb0b5a015133f915b8e1ce44c85e1ad6cf927eefe8b489aa014
SHA1 hash: 4c00d119abe684eb26a4273dc39ce48a0e5e5159
MD5 hash: 13e9d34a21f954c0b87f1ae5847ab925
humanhash: four-earth-hamper-sodium
File name:SWIFT.pdf.cab
Download: download sample
Signature AgentTesla
File size:357'854 bytes
First seen:2020-06-23 20:12:56 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:y+EqR/cHELllxjjyml1ooQ/mAqIrZOW4Upu26pqbDYzvw1u:yo/cHEH+6MwXUo2YqIzvp
TLSH 5C74235405A6C1C7751E79277CFAF8DE526FFCA6A709A34A45763C88C2E13C2DC1A0B2
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail9.sgnetway.net
Sending IP: 164.138.19.9
From: ProCredit Bank a.d. <Soudabeh.Tehrani@ptbnet.com>
Subject: Payment
Attachment: SWIFT.pdf.cab (contains "SWIFT.exe")

AgentTesla SMTP exfil server:
mail.napred.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-23 20:14:06 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab b78271cf652d50dfd1efc62c73cd6b3656649a7cdce2a4163d8cb8791bd295e1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments