MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 44ced9bfc843037c004c8f4d2ec8c984789433de0cda5907df5295bd9c9d695c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 44ced9bfc843037c004c8f4d2ec8c984789433de0cda5907df5295bd9c9d695c
SHA3-384 hash: cdb7f9fd4ec0f4a1c18e07ba7b655d3e18491323172adcde79a2756faa48462f4621cdad63319cdf20158c5139acb67b
SHA1 hash: 7e28d360cc65e6c41f8a5afe52a627ad48d157cd
MD5 hash: 136c3bdc9a6f2e5c7d60aa2179a38ca7
humanhash: blue-charlie-michigan-monkey
File name:Tracking No_SINI0068206497.gz
Download: download sample
Signature AgentTesla
File size:248'443 bytes
First seen:2020-07-02 05:03:40 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:wxCfDAfYF6jNxfFxwrg6kaVXR40HyEGzRC7BQPkd8auZQx1q3lg9:X8fnp3Grg6bO6yTRkQPkWauZQzWlY
TLSH 0D3423B731BE608F4AB160BC35450F09A7AE3248D5FA28DF071E25A290BBF53D4C1B59
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: "DHL EXPRESS" <info@power-vvin.com>
Received: from slot0.power-vvin.com (unknown [167.99.10.197])
Date: Thu, 02 Jul 2020 00:45:08 +0000
Subject: DHL PO1001910 Sample Arrive : Tracking No_SINI0068206497
Attachment: Tracking No_SINI0068206497.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-02 05:05:04 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 44ced9bfc843037c004c8f4d2ec8c984789433de0cda5907df5295bd9c9d695c

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments