MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d775cae27f36a3db519da89a1900aa53bb21958b99ac30a022a661ed80d7dc1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d775cae27f36a3db519da89a1900aa53bb21958b99ac30a022a661ed80d7dc1e
SHA3-384 hash: de7d72a42d3f6477c2c4af826cacf173a78ca2472ae3a7ef4bfca42a6af4a6372b12aa45059f1165c466a77d1e4be50a
SHA1 hash: 9c186e8b4efb2e8c44e81a20361fad45c54462d6
MD5 hash: cfe35134b9bc37d6262741559fdbca34
humanhash: robin-california-carolina-nitrogen
File name:Shipping Document.zip
Download: download sample
Signature AgentTesla
File size:1'299'762 bytes
First seen:2020-05-04 22:25:52 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:l8v9W5OzQZtmjfA0YZtimazJkPXq2pW3sGKVm44NfEH/uTIprnd:l845YQtmVQAkPawW8Pm4yfEH/Zd
TLSH 315533E9C969076F94292F00F016848685CBAE5DD04AC9E7F006E3328AD54FD7A71ADF
Reporter abuse_ch
Tags:AgentTesla DHL zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: saha.com
Sending IP: 173.82.245.51
From: DHL EXPRESS <buhimport@dhl.com>
Subject: Re: Your DHL Shipment AWB# 6326142421
Attachment: Shipping Document.zip (contains "Shipping Document.exe")

AgentTesla SMTP exfil server:
mail.elkat.com.my:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Androm
Status:
Malicious
First seen:
2020-05-04 22:36:45 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d775cae27f36a3db519da89a1900aa53bb21958b99ac30a022a661ed80d7dc1e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments