MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10b78017db0b6de67ae0e36e5f8a868ebe712478559f8536609b24a7fa78d675. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 10b78017db0b6de67ae0e36e5f8a868ebe712478559f8536609b24a7fa78d675
SHA3-384 hash: 26093d2399a1a84126357e3019f653c210e073e46a8e903581bd015bc6d7896a43350f50134cd4d6a1c08035325d4c5b
SHA1 hash: 2f2d5e42ef4e94c570ea0acb2e7a67427f87c0f4
MD5 hash: b056831a4fdfa5eed4b769f55b62f463
humanhash: johnny-skylark-vegan-happy
File name:Shipment Airway Bill_pdf.gz
Download: download sample
Signature AgentTesla
File size:513'348 bytes
First seen:2020-06-15 12:37:21 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:qEveho6AoFQmA14ic37Cfur8w+dZwtvKwmi62s:LY+3mhUrdZwgwmF2s
TLSH 14B4238EF07B3916DEC5A18E1669C8120A414D67CD16FC75FC231CB26A90DEE9F0D4A7
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server1.bluecloud.jo
Sending IP: 81.95.158.149
From: DHL EXPRESS <worldwide@dhl.com>
Subject: DHL Express shipment per-alert!!
Attachment: Shipment Airway Bill_pdf.gz (contains "Shipment Airway Bill_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-15 12:39:04 UTC
AV detection:
36 of 48 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 10b78017db0b6de67ae0e36e5f8a868ebe712478559f8536609b24a7fa78d675

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments