MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e7d07553fdf39fff545ff7cfe155b598f746c96aec21b0becf3a998610e2a60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1e7d07553fdf39fff545ff7cfe155b598f746c96aec21b0becf3a998610e2a60
SHA3-384 hash: 74862781a6d68a076683dd1e4a60736d8924e1763a076b1bdfe095ea21b045ce1de59d42a1b72ed349c33d0df1db3e2a
SHA1 hash: e6bc8fea95832670e2131db5a667e830f2766f0a
MD5 hash: 468bb0cc50c2fe9754015eaf4d63276c
humanhash: blossom-ten-louisiana-asparagus
File name:Original Shipping Documents_pdf.gz
Download: download sample
Signature AgentTesla
File size:429'587 bytes
First seen:2020-05-13 07:16:37 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:3B6jNqv55u98TB1YDwOAhtDhLyczzFRXvo:RGqh5u9G1YMOORzBBo
TLSH 7D94237AED307E35730A874DCC9AA8702CBCC6281B67AF57C585FA35B51FEC62108A51
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.vinylbannersprinting.co.uk
Sending IP: 217.174.249.10
From: DHL EXPRESS <worldwide@dhl.com>
Subject: Parcel Held At Our Facility (Arrival Notice)
Attachment: Original Shipping Documents_pdf.gz (contains "Original Shipping Documents_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Hploki
Status:
Malicious
First seen:
2020-05-13 07:36:41 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 1e7d07553fdf39fff545ff7cfe155b598f746c96aec21b0becf3a998610e2a60

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments