MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a73000a7e89e5e99c97da6f997ce0a937cd4743fdc6b5d068be092a3aa55eae4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a73000a7e89e5e99c97da6f997ce0a937cd4743fdc6b5d068be092a3aa55eae4
SHA3-384 hash: c165be1e1f36234f78e59754133aa28ad6f81172f5fbdc36aedc2be35512534647fc2b7b52884abbe76b8e60fb3c93f4
SHA1 hash: f2eef7ec0d05bfd707dd4c743dd65fe835abc3ca
MD5 hash: 43f5f44ff684a613d8c6f78fa593f7a0
humanhash: maine-comet-avocado-papa
File name:DHL Customer Service.zip
Download: download sample
Signature AgentTesla
File size:396'977 bytes
First seen:2020-05-13 10:07:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:F10c9hj8+hsg5F/GRSZMfmC1pvApDIZmj+kk0DjCTvFegRkk/k+NLp:Fqc9F8+hSA2vAtIQ/k0XQdegm6ksp
TLSH B38423D054D733FCA3DCD9B6021963B44B668143E9D00879A5239FF6F8F96AAF05860A
Reporter abuse_ch
Tags:AgentTesla DHL zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail2526.emaildomain.website
Sending IP: 209.239.119.154
From: DHL Customer Service <info@dhl.com>
Subject: Your Package has just arrived
Attachment: DHL Customer Service.zip (contains "DHL Customer Service..exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 10:36:52 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a73000a7e89e5e99c97da6f997ce0a937cd4743fdc6b5d068be092a3aa55eae4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments