MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0b202c7ac4e9ee1e5b48561829e162a64a43ddbf8f42ff04ab0f7dfda8d5f76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d0b202c7ac4e9ee1e5b48561829e162a64a43ddbf8f42ff04ab0f7dfda8d5f76
SHA3-384 hash: 28005591683d94c9dfcdfb612decbbc0acae65ebcc40ef853504fef787a417a424f0e4f22b09bb659ed0fb33a125972f
SHA1 hash: 5ff8b0f54ed45a8ddb52379b391503053818440b
MD5 hash: 9ae17951e031764fd40bd919cde9446e
humanhash: edward-muppet-william-paris
File name:DHL_3036875844.cab
Download: download sample
Signature AgentTesla
File size:502'216 bytes
First seen:2020-06-03 11:25:04 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:XaLWm4UtvRRpsWiJZJw5d3bTl5C/fVnCujQbOuzekB6I2:Xsn/tpwWiJnwvl5C/fbmelx
TLSH 6CB4234D6299D6CA630F35E4CAE0525A1D81720B2052B4BD3D7F54AA2E0EEF341D2DBC
Reporter abuse_ch
Tags:AgentTesla cab DHL HostGator


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gateway30.websitewelcome.com
Sending IP: 192.185.168.15
From: Mariela Cortés (DHL PE) <vdiestrac@dydcoprobise.com>
Subject: AVISO DE LLEGADA ENVIO CON GUIA DHL 3036875844
Attachment: DHL_3036875844.cab (contains "DHL_3036875844.exe")

AgentTesla SMTP exfil server:
mail.marketinfosales.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 11:38:01 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab d0b202c7ac4e9ee1e5b48561829e162a64a43ddbf8f42ff04ab0f7dfda8d5f76

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments