MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e7489db55d6b06f02689b796853cdd828aaf329487f92a709e92631a8126c197. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e7489db55d6b06f02689b796853cdd828aaf329487f92a709e92631a8126c197
SHA3-384 hash: 4e4a42582560f6a2139085f5b75b092205b8ff5cefd510c2b052dd15f35a2a74ffcbf5b840b93e9638c5026b3123f066
SHA1 hash: 36b7978a08709c7941266de0049989ebd51571a2
MD5 hash: 3e83e71898b6601e048d717ee6d36cb3
humanhash: five-item-oregon-mars
File name:AWB 82...616573.gz
Download: download sample
Signature AgentTesla
File size:487'943 bytes
First seen:2020-05-05 09:00:53 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:bqMG4PtyHjQvjfAtWI0Ekpf02YHlhBU4Odqrsg8hW7p81L8:+Z50bAuTy2YHlh9OE/gQ88
TLSH 0AA423997DE4729A6622BDC62B4745CED3B022403BCFCCD9DAF847252D2110511AEF6F
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pkz21-1-spamexpert1.hoster.kz
Sending IP: 185.111.104.140
From: DHL EXPRESS <trackingmail@dhl.com>
Subject: DHL Shipment Arrival Notification: AWB 8274616573
Attachment: AWB 82...616573.gz (contains "AWB 82...616573.exe")

AgentTesla SMTP exfil server:
smtp.znshenesolar.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-05-05 09:35:31 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
24 of 31 (77.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz e7489db55d6b06f02689b796853cdd828aaf329487f92a709e92631a8126c197

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments