MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efafbcd8c1833e58202139b5877cffdafff021bcb0b8da527e984db8d5f87e38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: efafbcd8c1833e58202139b5877cffdafff021bcb0b8da527e984db8d5f87e38
SHA3-384 hash: 369ba2ed37ffe83e89580cd319a94ab247274cfa3fbed0d3417a728d9d4ca7f9b8284faff3a5243fa265454326fc0ed6
SHA1 hash: abb0a0dd91252da795fd3117570d0db5a7b17d1f
MD5 hash: 6fb991930bd01b52cce4ac22418c6e8a
humanhash: ack-georgia-batman-leopard
File name:SWIFT_ADVICE.iso
Download: download sample
Signature AgentTesla
File size:661'504 bytes
First seen:2020-10-15 12:11:40 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:uaDQ/7uNQtgTPrv46g26VOfL8olbtPKSUXmDo2b+h28c++dtzV1/6SHjJosmJVsj:uaDQD/tyPr0OACOXmYLyLZ6Y1vhN
TLSH 2DE4D0226399AF75F17D677A24B0201047F5B142A332DB0E3EED52CC5AA3F405B32B5A
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: worldbank.org
Sending IP: 95.211.208.25
From: DBS BANK <aalatabani@worldbank.org>
Subject: PAYMENT ADVICE NOTIFICATION 14-10-20 (DBS
Attachment: SWIFT_ADVICE.iso (contains "SWIFT_ADVICE.exe")

AgentTesla SMTP exfil server:
mail.grandtours.gr:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Woreflint
Status:
Malicious
First seen:
2020-10-15 07:40:39 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso efafbcd8c1833e58202139b5877cffdafff021bcb0b8da527e984db8d5f87e38

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments