MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26280a570fac404d9d67633e3ebd4442866492e84fb52351f551547c80d529c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 26280a570fac404d9d67633e3ebd4442866492e84fb52351f551547c80d529c3
SHA3-384 hash: 61acb961120b86ce387095e0eb2b5629faa00d8b094530095ea2f5b261c0e4baa77a2f0b7c180e459bf24a5ab73a54f8
SHA1 hash: 323223cc7e37c1b91a4fb70617c124470c219001
MD5 hash: e0a56d2cfdfc732adb1c49dba43c8530
humanhash: yellow-carpet-bacon-diet
File name:DHL-Account Statement.iso
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-08-18 13:18:14 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:4xAbVGqMcOFV5PB7Uph9C0Zvi32MK/qXeBnXXdW6YUJCgvZc:1c+EPB7U39hZvi32MK/qXeDW6J8KG
TLSH 1645F1353698DA10D7BA5736CCD9610813FAF4026621DF6EFDDD215C0A61BA28B237CB
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.sap-express.com
Sending IP: 103.31.132.106
From: invoicequery@dhl.com
Subject: DHL STATEMENT OF ACCOUNT - Dated 18/08/2020
Attachment: DHL-Account Statement.iso (contains "DHL-Account Statement.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Bulz
Status:
Suspicious
First seen:
2020-08-18 13:20:07 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 26280a570fac404d9d67633e3ebd4442866492e84fb52351f551547c80d529c3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments