MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d705db8b864169f89c2544719290c9a768742fe6767e8d436c8be40ce3d998c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d705db8b864169f89c2544719290c9a768742fe6767e8d436c8be40ce3d998c9
SHA3-384 hash: f08416e9cec2003559d00c5177f5a85c15372b53ce443011f926957604d182b092d2d531a1a3077d0af1634ae4c6f653
SHA1 hash: 76b7b630a6085dbc5e6685c34e83ab21645e940f
MD5 hash: 42b30143eef665405eaa86258e78b286
humanhash: steak-timing-beer-indigo
File name:Dhl _SHIPPING DOC - 0036284639289.img
Download: download sample
Signature AgentTesla
File size:1'507'328 bytes
First seen:2020-08-17 06:12:08 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:Uq9CRixt4LFWJB0UWJ1J30s1nIiu88yQrv2wiABwRnXFdR54cmBqq9Z2:f0kuHbJPpl/QrXLun/ccmj9E
TLSH A8658D22B7907432C172167CDD3B63B4A82ABD112A28A9477BF45C4CBF3B6433975297
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.sekawan.com
Sending IP: 45.251.72.199
From: Dhlemailship <no-reply@dhl.com>
Subject: DHL : ARRIVAL NOTIFICATION!!! - SHIPPING DOC. COMMERCIAL INVOICE, BILL OF LADING, & PACKING LIST A // Tracking No : KCLGQOE191781
Attachment: Dhl _SHIPPING DOC - 0036284639289.img (contains "dhl.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-16 21:35:15 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img d705db8b864169f89c2544719290c9a768742fe6767e8d436c8be40ce3d998c9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments