MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfd394fa12f3bfd3a2707b4ccbe08da2d4c2e835eb1a1ad268f1c0ca1f425586. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bfd394fa12f3bfd3a2707b4ccbe08da2d4c2e835eb1a1ad268f1c0ca1f425586
SHA3-384 hash: 2444bd550c816c7724b07f7c87a871726a48494b522930c8071b670e7e104dfc1ac5beab99420da2d3239af334f17e7a
SHA1 hash: c37ebcf8fcc537ac47f7cbcf4965765a7312cbc4
MD5 hash: c55c0613ed492692a5632751a6b6e5ee
humanhash: mobile-triple-west-butter
File name:Halkbank.iso
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-06 17:30:26 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:nlgOo5V64GGxxmU7XS3uM/3FBFMiSWAVu:lj56xxHWB/fFyWAVu
TLSH AA4522006E58D96AC9984C3D597B7E104A78FF96D88593CB329C61A0777B3C14C0FAEE
Reporter abuse_ch
Tags:AgentTesla geo Halkbank iso TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 104.168.102.198
From: YINGLUCK INTERNATIONAL CHARITY FOUNDATION <yicfcharityfoundation2008@gmail.com>
Reply-To: YINGLUCK INTERNATIONAL CHARITY FOUNDATION <info.yingluckshinawatra@gmail.com>
Subject: SAVE A SOUL
Attachment: Halkbank.iso (contains "UME001.exe")

AgentTesla SMTP exfil server:
mail.bncledaydinlatma.com

AgentTesla SMTP exfil email address:
info@bncledaydinlatma.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-07 04:28:17 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso bfd394fa12f3bfd3a2707b4ccbe08da2d4c2e835eb1a1ad268f1c0ca1f425586

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments