MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ada4ced9f7d0cab6a176910065d0e953df430328342d42abbf6900a623a00be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1ada4ced9f7d0cab6a176910065d0e953df430328342d42abbf6900a623a00be
SHA3-384 hash: 02a0f6068a61b9b5aa54a5fa920d76ca172c3cd5e536bfc7d6a1e12fef9643246754731999e487e692876581c99be191
SHA1 hash: ab3f50c1d33d9c0596a078a661528d620d29611c
MD5 hash: a151dd9ffa61fe2247b26dfeeacf54d6
humanhash: ceiling-shade-white-delaware
File name:DHL Shipment_pdf.gz
Download: download sample
Signature AgentTesla
File size:462'564 bytes
First seen:2020-07-16 08:56:20 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:0Px4OqPsc6BUqpQhPsFQzoYuKCPJYLwTxohXR:e4fz6BUqaJeitQOcTGZR
TLSH 7DA4231CB28094A153B60B80F43B32DB18652917957DDC9718711CB23FA8A4EDF76B77
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: earth.dotsi.pt
Sending IP: 188.93.232.9
From: DHL EXPRESS <worldwide@dhl.com>
Subject: DHL Shippment Alert!!
Attachment: DHL Shipment_pdf.gz (contains "DHL Shipment_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-16 08:58:05 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 1ada4ced9f7d0cab6a176910065d0e953df430328342d42abbf6900a623a00be

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments