MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21e7b3f1f88fa986f1ed0f8feab664e9468b317aa9090576222d3eee5b84ae71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 21e7b3f1f88fa986f1ed0f8feab664e9468b317aa9090576222d3eee5b84ae71
SHA3-384 hash: 0911e1dab08bce08eee872780b806826c29126ff7c801805dfab6e463e261b452a70cc243adb1745050d1d2db76b31ea
SHA1 hash: c69f0ff212d617dfd8be0895057006727a2d878d
MD5 hash: e1587272785ac24babaad26f7b694b9e
humanhash: tennis-fourteen-golf-three
File name:DOCUMENTO DE ENVO.rar
Download: download sample
Signature AgentTesla
File size:389'402 bytes
First seen:2020-07-16 19:09:07 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:XKC/O0KxzDcKpLtVQIU1olXhYL+xwPiW5JrXFUhen7GhTct3rRMwysVxGtjkP3Ym:aC7sFLHQIUqVhwa4r72hSGCltMwhVxGu
TLSH DE842326D68D55142E4A9F6AFB370CDE992E893532FD032E8C3E491536FE60388CD136
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: rdns0.absean.com
Sending IP: 192.129.188.197
From: DHL worldwild <utilit-grade@absean.com>
Subject: Documento de envío (Factura, PI, Bill of Lading)
Attachment: DOCUMENTO DE ENVO.rar (contains "DOCUMENTO DE ENVÍO.exe")

AgentTesla SMTP exfil server:
mail.pierreinsurancebrokers.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 19:11:04 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 21e7b3f1f88fa986f1ed0f8feab664e9468b317aa9090576222d3eee5b84ae71

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments