MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8236d000f03a86fa9df277fbc63c0d49157fa9a170567a8db6d0d10ea606fc6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d8236d000f03a86fa9df277fbc63c0d49157fa9a170567a8db6d0d10ea606fc6
SHA3-384 hash: 94c7943e3c9bab33d6e184b00adf1a496d97dd17ec1aa838cc55450bdd728bb4756ba0b1bdc6b6b011ee9d27a7a0992d
SHA1 hash: 726951081c87ddffdf00f061c5508066228bfbe3
MD5 hash: a8d5e0b54719a61eba90ae50322de431
humanhash: high-uncle-lithium-mexico
File name:Swift Copy.gz
Download: download sample
Signature AgentTesla
File size:491'373 bytes
First seen:2020-08-18 13:18:42 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:E89Ao0r5JgNDfjzWi6mPyXemo2FSshxNOGcEaPIGySjJ:EgAorDf2mPyXo2LgGdMqSF
TLSH 47A423BD5AF58EFF0466E1E26201D042C6E9ED837B7717D84C226718BFE4C01452B6B6
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: craigwood.com.hk
Sending IP: 185.222.57.238
From: kay.feng <kay.feng@craigwood.com.hk>
Subject: RE: PANAPESCA PES50526 SWIFT
Attachment: Swift Copy.gz (contains "Swift Copy.exe")

AgentTesla SMTP exfil server:
smtp.airlndia.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-18 13:20:11 UTC
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz d8236d000f03a86fa9df277fbc63c0d49157fa9a170567a8db6d0d10ea606fc6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments