MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e368d95924ddc948aad9260cb078b20d8c4a744cda314e265048fc67eb39707. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1e368d95924ddc948aad9260cb078b20d8c4a744cda314e265048fc67eb39707
SHA3-384 hash: 38b66400737de672088c04ee9b5172e2729a445a1f3a7b976c9dc5630774fd3a1c32c85afbdfb5f6b8cad643325f6d07
SHA1 hash: a503820dd6fc5dad784d33752fe087323c693a72
MD5 hash: c6d2e31f42e20fd206303bd3f1677e3c
humanhash: oregon-potato-island-lake
File name:DHL SHIPPING DOCUMENTS.iso
Download: download sample
Signature AgentTesla
File size:383'565 bytes
First seen:2020-06-16 05:33:00 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:VstyGzPH9JuM1jCO8fNrzXmsGQBrUG2CW2cJpGtK4FynW5MbFyPfc5KS:0PHPf1jCOrsGKUhChkgK49f6KS
TLSH B884230E0AFA4E73CC86B59D8B6429271BB01D25E036C9FB3A155C23267F42EB57E065
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: DHL EXPRESS <Shital.Adecco@dhl.com>
Subject: Re: DHL SHIPMENT NOTIFICATION
Attachment: DHL SHIPPING DOCUMENTS.iso (contains "DHL SHIPPING DOCUMENTS.exe")

AgentTesla SMTP exfil server:
montana.co.ke:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-16 05:34:06 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 1e368d95924ddc948aad9260cb078b20d8c4a744cda314e265048fc67eb39707

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments