MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e0b70236c243483c40701b1e4ed062bd88e58ed37f9678a28078e36a5b82b39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7e0b70236c243483c40701b1e4ed062bd88e58ed37f9678a28078e36a5b82b39
SHA3-384 hash: 3811d3c79e7505591287f7822324fdf962ebb1fdbaaf76f6923c73b50afe5c73e0d99b1e1c247d5e50e9a11e8feb3cb7
SHA1 hash: 5d7ef89df65430a8d2ab25588cbe7ac7aae0637e
MD5 hash: f860dcf8a176597f7e7a9dfae98a37e0
humanhash: tango-grey-saturn-neptune
File name:DHL-RECEIPT1.rar
Download: download sample
Signature AgentTesla
File size:552'964 bytes
First seen:2020-05-06 08:38:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:sViJoV9jNo63yE/OORWnJV2ap5bzTk9x5lEsLJPKfIQI50:sVxVt1DRMnFp5bXk9x5lEJQ150
TLSH 58C423BBA194CB9C44CBB3F6E52BA3D763CD058B59ABD8B728608D5C54CC01C46E463D
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dhl.com
Sending IP: 45.142.166.73
From: DHL=Delievery ServiceĀ® <noreply@dhl.com>
Subject: DHL=Bill OF Lading DOCUMENT/INVOICE AWB Number: 6278216789
Attachment: DHL-RECEIPT1.rar (contains "ge89e9z0GhphRJE.exe")

AgentTesla SMTP exil server:
smtp.anding-tw.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-06 09:35:37 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 7e0b70236c243483c40701b1e4ed062bd88e58ed37f9678a28078e36a5b82b39

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments