MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 17404d50f06f19e9d76465b9fb22bcb83eb61723deff48f856f95e5dad5dbf99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 17404d50f06f19e9d76465b9fb22bcb83eb61723deff48f856f95e5dad5dbf99
SHA3-384 hash: d6b927bc49c7a3c6f80a1fb073746844ad1dd3181f59e39ecc18b25ee754067030beb78b2f21fd7e026b47fa060c5776
SHA1 hash: 69d2cec61f7ee7a3af470d65d9b3100e65487cc2
MD5 hash: 9a6eeaaab79b83bb687c60dc4f5c57e0
humanhash: charlie-potato-crazy-lion
File name:IMG-COPYB840284-SCAN-2020-07-05-DOCUMENT-PDF.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-08 07:00:09 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:D/gl+acY+73cm9SImNatH01SAZ5k4oCkkWglW7ihjyBbA:7acY+73cmUImEH0gA/o9zgG+eBbA
TLSH E245DF387758663FC6FD43BB90A6120EB3F5C164228BEBA5986314E3170B352F5A7247
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: box.companyloyel.gq
Sending IP: 107.191.111.77
From: DHL EXPRESS <contacts@companyloyel.gq>
Subject: REMINDER: DHL Pending Notification/DHL_AWB_0011179303/AD
Attachment: IMG-COPYB840284-SCAN-2020-07-05-DOCUMENT-PDF.img (contains "IMG-COPYB840284-SCAN-2020-07-05-DOCUMENT-PDF.exe")

AgentTesla SMTP exfil server:
mail.i-breathe-co.tk:587 (104.168.184.70)

AgentTesla SMTP exfil email address:
keylogger-result@i-breathe-co.tk

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-08 07:36:06 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 17404d50f06f19e9d76465b9fb22bcb83eb61723deff48f856f95e5dad5dbf99

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments