MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7c66bca911d0a90e39b343519a2be5746479b71d0ebdc02b798c3aa44c7e852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a7c66bca911d0a90e39b343519a2be5746479b71d0ebdc02b798c3aa44c7e852
SHA3-384 hash: 815066307125783526785c49e0a5cf740cb865719673ce6ae04c467b76e2e68a0508ca3f1bd778fe5382a614ea5518cd
SHA1 hash: 4f90de0c0fb3ea2477dce82542cfac9e574183ac
MD5 hash: 1551d923b1067da2bbe2423f704d602c
humanhash: summer-comet-autumn-magazine
File name:DHL_07082020_AWN_07082020_INV_07082020.img
Download: download sample
Signature AgentTesla
File size:778'240 bytes
First seen:2020-08-10 09:57:54 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:XeuQxLfjgMQtQ78YgQ8dNzvH9hyWDfAGc302mj/y:XUxjj+Q785NzPDzSk3/
TLSH C8F48D5C9D6C0D16DD1427B78118A81E22A9AD56BBF1E5DF3F86314B43BDBF083B0229
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: noreply@dhl.com
Subject: DHL Express Shipment Confirmation
Attachment: DHL_07082020_AWN_07082020_INV_07082020.img (contains "DHL_07082020_AWN_07082020_INV_07082020.exe")

AgentTesla SMTP exfil server:
smtp.knmbz.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-10 09:59:06 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img a7c66bca911d0a90e39b343519a2be5746479b71d0ebdc02b798c3aa44c7e852

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments