MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11bc4052f40ce768086bb8e8ff4caef59e3f8acdb11493303f3ecb047f9afa8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 11bc4052f40ce768086bb8e8ff4caef59e3f8acdb11493303f3ecb047f9afa8c
SHA3-384 hash: 7ea89e6b1cb3dd2a4258583bbefa845f28804e2bdb3674e9edb6dc74c977fb66ed3885c12927673fe23a95ece059389f
SHA1 hash: 45e0ec89b8814740e115adf471e6071f7d2238e1
MD5 hash: 561d7a7d89c2b29661792e49b69f91a4
humanhash: six-tennessee-timing-high
File name:Original Invoice PLBL Draft.img
Download: download sample
Signature AgentTesla
File size:657'408 bytes
First seen:2020-06-29 06:13:54 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:xEpYsENNLYuJnmfU8RD1QkaAYwWWwoUn7zwONfeQ8875:x97TtJoTr1ET7MONfH88
TLSH 3CE44B2D3E80B816D63D493240B969906372E5875702C70F7ACE6BBC6F523DB3B462D9
Reporter abuse_ch
Tags:AgentTesla img TNT


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.620.xianwongleepxc.casa
Sending IP: 138.197.0.217
From: TNT EXPRESS <service@tnt.com>
Subject: CONSIGNMENT NOTIFICATION: You Have A Package With Us
Attachment: Original Invoice PLBL Draft.img (contains "Original Invoice PL&BL Draft.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Woreflint
Status:
Malicious
First seen:
2020-06-29 06:15:07 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 11bc4052f40ce768086bb8e8ff4caef59e3f8acdb11493303f3ecb047f9afa8c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments