MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf5dca0d89cf3c5df1f7c4efdd6b830450982355316dd18d77ac1f338f191852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cf5dca0d89cf3c5df1f7c4efdd6b830450982355316dd18d77ac1f338f191852
SHA3-384 hash: 68279026e6f35b9fcecd47dbaf0f5e75ab5185f4c7594070feed187c92e62a5a0591ddd3ee14afba781b07cad5b9f3b4
SHA1 hash: 462e0cbfd2269178a753a07b675f4b82fd7a94d0
MD5 hash: efbe316dbae1f5e2e91e24db84062e3e
humanhash: king-burger-sad-comet
File name:shipment airway bill_pdf.gz
Download: download sample
Signature AgentTesla
File size:478'899 bytes
First seen:2020-04-30 06:46:15 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:2KWpgyzktWZFHKZ80/cOLpW+8COElS3ClkbEcia3x:LWpJzktWvEjEOE+7OmSyuESx
TLSH E7A4239B17F9741981E1B2BF1D1F4DE4C844973C160D377AD4BE6CE20ABA8E650F2928
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.vinylbannersprinting.co.uk
Sending IP: 217.174.249.10
From: DHL EXPRESS <worldwide@dhl.com>
Subject: DHL Express shipment per-alert!!
Attachment: shipment airway bill_pdf.gz (contains "shipment airway bill_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-30 17:57:14 UTC
File Type:
Binary (Archive)
Extracted files:
39
AV detection:
28 of 48 (58.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz cf5dca0d89cf3c5df1f7c4efdd6b830450982355316dd18d77ac1f338f191852

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments