MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59ea4aba488091841cdd8108dd4d423fe6020ee97240c2d903cbd1e167051472. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 59ea4aba488091841cdd8108dd4d423fe6020ee97240c2d903cbd1e167051472
SHA3-384 hash: 8baf4ccd1708851de84ab59f8cc48450959eedfcf1064dc8f7ff7a37b506a5fbc7b1499d2440b0fb42b1e26ba8154311
SHA1 hash: 09f74694fc854612e1eaa94b37ae940373affbc2
MD5 hash: 1977ec35a09dc9e87d05a04c563d1872
humanhash: north-orange-colorado-yankee
File name:Delivery Note - AWD 209499488486-575745845845845.gz
Download: download sample
Signature AgentTesla
File size:1'041'388 bytes
First seen:2020-05-12 11:59:58 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:Zf5OEb6OuP8qwzrqvQBxkso6/L+/6MnDapnnnpF7rdI:ZcEbnqaMQnkso6/LJMwnT7rdI
TLSH 1F2533B4418CEB82C882C51CAE3FE0DDE5AAC545895F60F171E921F43AB4897FA51E1F
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.dz-techgroup.it
Sending IP: 217.61.37.47
From: DHL Express <katewright_dhl@gmail.com>
Subject: Failed DHL Delivery Notification
Attachment: Delivery Note - AWD 209499488486-575745845845845.gz (contains "Delivery Note - AWD 209499488486-575745845845845.exe")

AgentTesla FTP exfil server:
66.45.232.205:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-12 12:42:03 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 59ea4aba488091841cdd8108dd4d423fe6020ee97240c2d903cbd1e167051472

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments