MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33608fdb728de9e87dc8cd871b832ee4de4c019c552017f45ba854acdac0d634. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 33608fdb728de9e87dc8cd871b832ee4de4c019c552017f45ba854acdac0d634
SHA3-384 hash: a87844ed81ba19a8e41f7bc9e4c785bf7c1129787b9b5a10a31693a386005613e17df382d87950f305f1427b800961b4
SHA1 hash: 5b2cd74f8d082f4ff24e0036b0ccdaebe51a8914
MD5 hash: 41c29f0547e6179c01fefa8b7afc42e2
humanhash: wolfram-pasta-network-whiskey
File name:Bill of Lading_pdf.gz
Download: download sample
Signature AgentTesla
File size:450'563 bytes
First seen:2020-07-01 10:26:58 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:D0QAKJATYoAkDZA8Dk5wh5mUUMX7T8AT84Y:DnAKJATYoAMeaLLVE
TLSH 35A4231E6F5027A80EE87F39EBB5B68C2C503022658C6BF3D507D99804AD791F4BBC61
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vmh18397.hosting24.com.au
Sending IP: 103.237.108.115
From: COSCO SHIPPING INC <support@coscoexpress.com>
Subject: ORIGINAL B/L DOCUMENT / PL
Attachment: Bill of Lading_pdf.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-01 10:28:07 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 33608fdb728de9e87dc8cd871b832ee4de4c019c552017f45ba854acdac0d634

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments