MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20186fb287c72cadcbf4f38bceaec534bb0ef586f770695e326eb59c9f73e383. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 20186fb287c72cadcbf4f38bceaec534bb0ef586f770695e326eb59c9f73e383
SHA3-384 hash: 1e118ca44a157bb2b46b0d14386046ed9fdc3b38667f19d4668bd244b29013339858f22c10215c508305ee62f6d796c7
SHA1 hash: 5169b444997f6af36b789e08333b0e8edabd0bb0
MD5 hash: 9d7020c0b89869da813c2967bd6b8e1b
humanhash: ceiling-summer-lamp-wolfram
File name:DHL-SZX033892291.z
Download: download sample
Signature AgentTesla
File size:523'085 bytes
First seen:2020-07-09 07:40:34 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:2LlwI+U6xb7MhEq+zXN+oEGlbEx5cwse3vKUpJL73rnqW89nam1:2hwI+UaYhIXdEGlbEbrKUpR73pQaU
TLSH 70B423DC2E7A459B9E4C068A3B5FC0863A6D49E9F758CE3D2D1027A0281F847E51DF1E
Reporter abuse_ch
Tags:AgentTesla DHL z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: m13231.mail.qiye.163.com
Sending IP: 220.181.13.231
From: tim xu(SZX GTW) (DHL CN) <ct@cgerhardt.net>
Subject: DHL Shipment In Transit
Attachment: DHL-SZX033892291.z (contains "DHL-SZX033892291.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-09 07:42:08 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 20186fb287c72cadcbf4f38bceaec534bb0ef586f770695e326eb59c9f73e383

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments