MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ac39decf91cdbf8f1b979a562d7d4931623173c70520a414e317770062f7fec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8ac39decf91cdbf8f1b979a562d7d4931623173c70520a414e317770062f7fec
SHA3-384 hash: c3d97890149df50b7f2529d1db2e1c0be27f3bf665804f4143bcf918ffcace586471d165ac99588f232b9cb27ba42296
SHA1 hash: b7b3ae688fa59b30805c05a1e7736159809aa244
MD5 hash: 3004fb0ce37e1b4b38e11d2a213f2719
humanhash: zebra-iowa-lemon-seven
File name:DHL CUSTOMER ADVISORY BL COM. INV. 7098216766.r27
Download: download sample
Signature AgentTesla
File size:1'257'444 bytes
First seen:2020-05-04 21:12:07 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:GAu9T8Egx11vrf4rzMrmlHqZV+gOIOjNa4kVWUgsxQNvY0SvTa:Lu9Yhx11T4E7WgKlU7svY0ea
TLSH 8445337350AE47B9CB1E6A7771C819DF46A985034F28816C8874973444BBEE4E7BB2CC
Reporter abuse_ch
Tags:AgentTesla DHL r27


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dhl.com
Sending IP: 191.101.130.212
From: DHL<NoReply@dhl.com>
Reply-To: nofia.putri.siemens.com@bk.ru
Subject: DHL Shipment Notification : 7098216766
Attachment: DHL CUSTOMER ADVISORY BL COM. INV. 7098216766.r27 (contains "DHL CUSTOMER ADVISORY BL COM. INV. 7098216766.exe")

AgentTesla SMTP exfil server:
mail.zarkom.rs:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-04 19:36:00 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8ac39decf91cdbf8f1b979a562d7d4931623173c70520a414e317770062f7fec

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments