MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 130207ed5c29de5fd5845f8ce6fbea0a4a24678d6248304cda011dcc76aa0702. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 130207ed5c29de5fd5845f8ce6fbea0a4a24678d6248304cda011dcc76aa0702
SHA3-384 hash: 52cde9800756d7c6bf7272a3f79ef33352041500c46fb5d516e81b76ea04adf095fec5317e2e2fb648c3858efce1d589
SHA1 hash: 2548c6228bccac39e87f3113395aeb3c396d9a2f
MD5 hash: 66566574a64633001f8c22a2ea5c3f17
humanhash: avocado-magazine-spring-stairway
File name:SHIPMENT DETAILS.r01
Download: download sample
Signature AgentTesla
File size:410'196 bytes
First seen:2020-06-15 12:43:30 UTC
Last seen:Never
File type: r01
MIME type:application/x-rar
ssdeep 6144:VsrNIDji76Gmfi82Cz5MgZGGbvr+5uxUCRWdTxnhdLyXKQTL8N5sL3DwSfbokO9I:Vsjehz5MAGQrjUCeNhhypfG5G3qToT
TLSH 639423BA17BB4A10A91588D6EC4DCF7F6C33E802C42DE5A7C952B562BD23E4C5CC51E2
Reporter abuse_ch
Tags:AgentTesla DHL r01


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.taie.ca
Sending IP: 198.1.127.248
From: DHL Express <support@dhl.com>
Subject: DHL Import Clearance – Consignment : #600595460
Attachment: SHIPMENT DETAILS.r01 (contains "SHIPMENT DETAILS.exe")

AgentTesla SMTP exfil server:
smtp.t-oniline.me:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-06-15 12:45:07 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r01 130207ed5c29de5fd5845f8ce6fbea0a4a24678d6248304cda011dcc76aa0702

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments