MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d685fb1b860b06f09e08cfc945081c65f876d7004b979936dadd7bd73a11edf4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d685fb1b860b06f09e08cfc945081c65f876d7004b979936dadd7bd73a11edf4
SHA3-384 hash: 28f0bb06880e2af336efad39b1fa6544b25f61640fdc6d2819c57fcd4a76e3235e0fa2d30abc1326f2f6c4d979c64643
SHA1 hash: 446e53a1d93826ecf974201a4a1e3a4e7a5a1028
MD5 hash: 06573e2cfa556829572aa80f721d9435
humanhash: six-one-colorado-network
File name:HSBC TRANSFER COPY00010202020_pdf.rar
Download: download sample
Signature AgentTesla
File size:762'784 bytes
First seen:2020-10-21 07:00:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:oIZ3PbpAgGsCYIp1mAL3d+pHXpCeIqq+j8hcYj+8gPzVfI9WVNusz+rtZ3DCw:xZ3lAgsXmARQCz+j8Rj+fz5iWTjz6tJ
TLSH 75F42331ECBC630C1B8F0EB84EF5E5CF22BABA86291534F45461F089B616DAF5510BD6
Reporter abuse_ch
Tags:AgentTesla HSBC rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: m1mkyc5j.ni.net.tr
Sending IP: 89.252.168.52
From: HSBC Advising Service <advising.service.458060800.904852.3096473270@mail.hsbcnet.hsbc.com>
Reply-To: beltaseliina@gmail.com
Subject: Payment Advice - Advice Ref:[GLVA06282529]
Attachment: HSBC TRANSFER COPY00010202020_pdf.rar (contains "HSBC TRANSFER COPY00010202020_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Androm
Status:
Malicious
First seen:
2020-10-20 17:19:54 UTC
AV detection:
18 of 28 (64.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d685fb1b860b06f09e08cfc945081c65f876d7004b979936dadd7bd73a11edf4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments