MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf6b036abc775948bf316df025754790d809c584a14a5bd8a4d276c02092c1a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cf6b036abc775948bf316df025754790d809c584a14a5bd8a4d276c02092c1a6
SHA3-384 hash: 4f70c17a05d6d4162444b353ec9a02a7a8e8ebacb0ecab2679916c3cf5cd3f1da168e2109907fd97133b05e01ede9dc7
SHA1 hash: 0d724b9936a8478c0cd35c0d3627f07be661bf81
MD5 hash: 3034d704a1ccd37e911f94d9eeecb696
humanhash: blossom-mountain-wisconsin-beryllium
File name:Bank-Swift Copy.rar
Download: download sample
Signature AgentTesla
File size:408'998 bytes
First seen:2020-06-12 06:37:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:YITiS2NjRQEVw2lsHYtue5GoSWG8+0u7F1SjsdSg1fsC:PTi/QYwosHYtuefSaI1fsC
TLSH 5894239DBF66900004D9D7D3DBCBB9726E869A1E04ADE81D7867CB801C10E606FB6C97
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: carbosynth.com
Sending IP: 193.56.28.145
From: Auditor<accounts@carbosynth.com>
Reply-To: Auditor<suada042@gmail.com>
Subject: Fwd: Paid Invoices
Attachment: Bank-Swift Copy.rar (contains "Bank-Swift Copy.exe")

AgentTesla SMTP exfil server:
mail.zeusinfratech.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-12 06:39:06 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar cf6b036abc775948bf316df025754790d809c584a14a5bd8a4d276c02092c1a6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments