MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 256487f56f6ad99c043971e91572ccbe41f80b2f3e4a784323b483968c02d203. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 256487f56f6ad99c043971e91572ccbe41f80b2f3e4a784323b483968c02d203
SHA3-384 hash: eff7a96a3f6e2a7b1c0b687fe0ac79653df39e3579f8bf8af4fcc90cbc9326f8b22de7225cb32b5d6984b1699dabde04
SHA1 hash: 570be79855dfb807cdac77e95d812af57babbe0f
MD5 hash: 06d050383216bc294a757e62663487f2
humanhash: kitten-pizza-spring-texas
File name:Shipmment Details.doc..zip
Download: download sample
Signature AgentTesla
File size:399'846 bytes
First seen:2020-05-11 14:18:39 UTC
Last seen:2020-05-12 04:24:54 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:fA5dj57H0v4XWuEv8JuJBANHxJBlEDxxfLxMv0z:CdlyqJy80TQVCltk0z
TLSH A7842330452D28FB2E1F7B1D03BC29A9B22868F57DB54BFD6E0538439B524B6E9D2053
Reporter abuse_ch
Tags:AgentTesla DHL zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dhl.com
Sending IP: 103.99.1.174
From: DHL express<express@dhl.com>
Subject: Shipment Arrival Notice
Attachment: Shipmment Details.doc..zip (contains "Shipmment Details.doc..exe")

AgentTesla SMTP exfil server:
mail.hotel71.com.bd:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 14:36:50 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 256487f56f6ad99c043971e91572ccbe41f80b2f3e4a784323b483968c02d203

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments