MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a86a8d4e37899d844d336ee6df9a0ea4633ea621ed92daca640dbe4205a7374. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4a86a8d4e37899d844d336ee6df9a0ea4633ea621ed92daca640dbe4205a7374
SHA3-384 hash: 11f0817f4c7e7c1ef56868a1ec9d742150d0ab1be475b458197e62d007a7d615e2b0859ee5a132e63eaedb2af84dcaac
SHA1 hash: 71dda7bf3ef7f4a69c6457c387732ab8e7d98738
MD5 hash: 7a304897bbcc43dbce6b2b17a86fc3e5
humanhash: jig-monkey-robin-one
File name:YOUR DHL NOTIFICATION_PDF.gz
Download: download sample
Signature AgentTesla
File size:398'398 bytes
First seen:2020-06-15 12:05:35 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:qhnu8zppNHDRidWGaCOKDGxbwVRsBhqE812q:Knu4pNHdiNaCO4G1wVRsHqTQq
TLSH 268423D01F9EDB8C293147D941685F1BDC40743E91E25BF6A90B6B1B9F08AABD628D30
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: globe3email.hostcentral.net
Sending IP: 103.53.172.34
From: DHL EXPRESS <NoReply.ODD@dhl.com>
Subject: YOUR DHL NOTIFICATION/UPDATE PARCEL NO:DL7593462
Attachment: YOUR DHL NOTIFICATION_PDF.gz (contains "YOUR DHL NOTIFICATION_PDF.exe")

AgentTesla SMTP exfil server:
mail.greebals.gr:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Ransomware.WannaCry
Status:
Malicious
First seen:
2020-06-15 12:07:05 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 4a86a8d4e37899d844d336ee6df9a0ea4633ea621ed92daca640dbe4205a7374

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments