MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d6ca053a2ac5c09983962590775c4b751d4efc2ffade69b2751bc02c6453c179. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | d6ca053a2ac5c09983962590775c4b751d4efc2ffade69b2751bc02c6453c179 |
|---|---|
| SHA3-384 hash: | 2cc0cb8269b36d0fec76d3f4a2356e0622d0073c21eefd6a87294381282ba8197a370017993db521f56c429f691d03e8 |
| SHA1 hash: | ae43c4cfd37e0a95f85876b87c81697c29f26e36 |
| MD5 hash: | f4cc0bdd85acaeccbe018526118e60f5 |
| humanhash: | muppet-quebec-magazine-august |
| File name: | shipping documents.pdf.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 397'461 bytes |
| First seen: | 2020-06-14 10:40:05 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 12288:RJt/r5/v+aYmIVYdDz5fhHUZnYDWd3SSwL8np3Idt:RLD5/v+jzOh1ynYqI4Ydt |
| TLSH | 22842302D32D9AE777CF713AFD4E1A1F0119E4381AD72046EE87C923959D5B346223AB |
| Reporter | |
| Tags: | AgentTesla z |
cocaman
Malicious emailFrom: DHL Express <Jason.Fan@amassfreight.com>
Received: from amassfreight.com (unknown [37.48.85.217])
Date: 14 Jun 2020 04:22:46 -0700
Subject: DHL PACKAGE
Attachment: shipping documents.pdf.z
Intelligence
File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-06-14 10:42:04 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
19 of 31 (61.29%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.