MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82caa63c036a0ea17fbceafb6d978c70d37e2475960f8a4d40ad4014e5eef95b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 82caa63c036a0ea17fbceafb6d978c70d37e2475960f8a4d40ad4014e5eef95b
SHA3-384 hash: 77d4c9318b932bea3c8f303230dbe2068783cf8f016999581389f62fd0b02967e3d1eeb1140974c48ef27ebc07735fc1
SHA1 hash: 534c8391ffca387650f629e5bd15f586c30cc8d1
MD5 hash: 80ab9d8d34bb8471a2d7558dbed2f472
humanhash: berlin-steak-ohio-bacon
File name:DHL_FORM-PDF.rar
Download: download sample
Signature AgentTesla
File size:399'507 bytes
First seen:2020-06-04 06:32:50 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:bzauskodRVUh4yHHUpOPyjwjOg+GW9usOvH1Ut:SusqmyBajwjOT0Hm
TLSH 29842332B928D301691C2FA583B4A4437F9E7FD97203BA25913DE665A6F126C124E337
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mta.digitalsol.ro
Sending IP: 83.103.255.85
From: LIVRARE DHL EXPRESS <dhl.elp@dhl.com>
Reply-To: webmaster@e-gradinarit.ro
Subject: LIVRARE DHL (NOTIFICARE ECHILIERÄ‚)
Attachment: DHL_FORM-PDF.rar (contains "zy1lugWjpze0gyq.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 05:09:34 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 82caa63c036a0ea17fbceafb6d978c70d37e2475960f8a4d40ad4014e5eef95b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments