MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8bf91d8e964d95780dc9cf0337ec8fb3ef76e084c059af9fe9806a795d0b1c39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8bf91d8e964d95780dc9cf0337ec8fb3ef76e084c059af9fe9806a795d0b1c39
SHA3-384 hash: 61a13df93485ce5caf378ef3f2f83d2a9e7a699b1b8a6632ace6d21407dbb790fea1ff33f432984cfed642a09ae5cf04
SHA1 hash: 70d85cc304e267f2ac4e2e5d94285aa8a260cd1d
MD5 hash: 84cdd2960e466d5b1afdf09b21419fcd
humanhash: sweet-violet-glucose-arkansas
File name:DHL A8002742088-Contact form.pdf.z
Download: download sample
Signature AgentTesla
File size:437'748 bytes
First seen:2020-04-30 09:50:36 UTC
Last seen:2020-04-30 09:50:42 UTC
File type: z
MIME type:application/x-rar
ssdeep 6144:id1ieOGhnJo/z9X4SC3u7UDbvxu3BY2kM7bmC+jm7R6FyBGypu/RocAzFkl/D:jeOGhO/xISC+4bNMZ+Wky8QMGp5Ub
TLSH B894239B1E6251DC36200B71C0B01B49FF69789C1FA95C23B2D9D8909C77AFE1175B83
Reporter abuse_ch
Tags:AgentTesla DHL z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: newlinux4.pouyasazan.org
Sending IP: 94.130.255.202
From: DHL Express <info@behdisgroup.com>
Subject: Reference: GOT / 731104 :: Arrival Notice
Attachment: DHL A8002742088-Contact form.pdf.z (contains "DHL A8002742088-Contact form.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-30 10:36:47 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 8bf91d8e964d95780dc9cf0337ec8fb3ef76e084c059af9fe9806a795d0b1c39

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments