MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9ec683f1c0016569ef772352c238d15de0550839a6ba7d5a44d42207c1f27b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b9ec683f1c0016569ef772352c238d15de0550839a6ba7d5a44d42207c1f27b1
SHA3-384 hash: 8441582595699eaefd69304e587352dc9c5322e9b80004079b931659807b16f5503c771d93bd5729e0ace070e0294b14
SHA1 hash: eab157ea3388df80e4b0f4b0152aa92933dd7d5b
MD5 hash: e114507b77db44a8717a5351b47e30c1
humanhash: hot-river-minnesota-low
File name:customers_dhl-form.img
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-07-07 08:43:22 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:aFp3UraHEFVRoYoxZsUXBQCo3XK3VAcWGMJuD:sp3UekF5obJx0Kq2
TLSH 8F55F82C7B82641ADD3E06310465CEF0E271BC866A11C38F79CA7A693F3269F67150DE
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mohsen.mrservers.net
Sending IP: 148.251.177.142
From: DHL Express <customersservice@dhl.com>
Subject: DHL EzyBill – Invoice No: TNSR000153181
Attachment: customers_dhl-form.img (contains "customers_dhl-form.exe")

AgentTesla SMTP exfil server:
smtp.petroleumintegrated-ae.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Bluteal
Status:
Malicious
First seen:
2020-07-07 08:45:08 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img b9ec683f1c0016569ef772352c238d15de0550839a6ba7d5a44d42207c1f27b1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments