MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6972047ccf6f5155a2aae64086fb4667ef41ac7593e1b95ef03fb25d1bdf016b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6972047ccf6f5155a2aae64086fb4667ef41ac7593e1b95ef03fb25d1bdf016b
SHA3-384 hash: 50afad47227260afbee7b067d443ceb369665343ae2620f3d2049492783224d5b7e7caf878b7094874f2825dfd781c4e
SHA1 hash: 9626ff061c3eeb80369a8f856d43e889bae8f09d
MD5 hash: fb917f40a21b3c1c8520710c86afd109
humanhash: sink-west-twelve-missouri
File name:Delivery Note_PDF.rar
Download: download sample
Signature AgentTesla
File size:401'934 bytes
First seen:2020-08-05 08:47:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:vF0tBmvlzKs5jb8Cgwg6UnPgq77ZjSFmUf:vFgmvRKQjQCR1I9nZjRUf
TLSH E88423C8F81889D9AE51B0C4EB17B66FA4DDC0577206029A2D67A24F13BD301B599FF3
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: newton.britanico.cl
Sending IP: 200.29.19.155
From: DHL Express <service@dhl.com>
Subject: DHL CONSIGNMENT NOTIFICATION: AWB//733918737WA
Attachment: Delivery Note_PDF.rar (contains "Delivery Note_PDF.exe")

AgentTesla SMTP exfil server:
smtp.skybarnds.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-05 08:49:08 UTC
AV detection:
18 of 28 (64.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 6972047ccf6f5155a2aae64086fb4667ef41ac7593e1b95ef03fb25d1bdf016b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments