MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb0772397bb29d18c940448db5d3df7f8bd956e64fe168bc33b1abcb8cc6f924. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bb0772397bb29d18c940448db5d3df7f8bd956e64fe168bc33b1abcb8cc6f924
SHA3-384 hash: 10efb67c6131d2c2c9b89598b54e69fdcf0d5c5dccaed3a3bbd6e723c86aff566b5b0e5a34b56ab2ef8248a2394cbab1
SHA1 hash: ec2c43f2cbf70080cfe84dcb0294f138d9c9edb9
MD5 hash: 2ff6d28b113b5dffa655ebc6d60ffc99
humanhash: robin-massachusetts-neptune-lake
File name:Account details.gz
Download: download sample
Signature AgentTesla
File size:464'998 bytes
First seen:2020-06-22 06:46:45 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:usxQRtNE470HsYaG/r8Sb4CwjzV6Wimx5l/MF+Onbk5m/Z:u3RnE4gsYrIzl6iDhk+OnA5m/Z
TLSH 4FA42384578A8FC0856326248F5540A6DBB4ED697061EE7AF52303FD63850ADFFC46B3
Reporter abuse_ch
Tags:AgentTesla gz HSBC


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.826.ganniobunn.casa
Sending IP: 64.227.76.217
From: HSBC BANK <noreply@hsbc.co.uk>
Subject: Re: Account details confirmation
Attachment: Account details.gz (contains "Account details.exe")

AgentTesla SMTP exfil server:
mail.salkic.co.ba:587

AgentTesla SMTP exfil email address:
ch@odumejeh.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-22 06:48:04 UTC
AV detection:
35 of 47 (74.47%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz bb0772397bb29d18c940448db5d3df7f8bd956e64fe168bc33b1abcb8cc6f924

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments