MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 39c80732d4711be5d913bf91f29c5aa3dc97029ef58a0afb56f98f0a274156c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 39c80732d4711be5d913bf91f29c5aa3dc97029ef58a0afb56f98f0a274156c8
SHA3-384 hash: 7eaf76f75cb9e0a49a64fb9e46915f8924c41d857d7edcc34cc41633aae4a2ff201f5f2609c6ea1b52f4169547e50727
SHA1 hash: e8e0de834b28e81cdc1609f7a5a6b50123f4276d
MD5 hash: 2284b4ffa91243c676bdcb6e9549d4b7
humanhash: november-kitten-happy-spring
File name:0JUTc25GRpDD0dA.rar
Download: download sample
Signature AgentTesla
File size:405'503 bytes
First seen:2020-05-25 08:01:29 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:FZQbY+T61pn1EcAEncirCmy/yRVmPe56DWUl:FZQbNOpAocirCx/EGey
TLSH 558423C124F9A97E8811FDB44E7DC87A7F7B01E1FB45E1A2D89C3A31A334605A29547C
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zcsmta02.asyst.co.id
Sending IP: 103.9.36.45
From: DHL Express <NO-Reply-DHL@suzuki.co.th>
Subject: DHL Express Courier:Incomplete Delivery To Your Shipping Address
Attachment: 0JUTc25GRpDD0dA.rar (contains "0JUTc25GRpDD0dA.exe")

AgentTesla SMTP exfil server:
mail.fsicibd.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-25 08:36:10 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 39c80732d4711be5d913bf91f29c5aa3dc97029ef58a0afb56f98f0a274156c8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments