MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b6f18ec15fa431a4ad7cda366c67d81a574e2a5bfa339ef3f46b6aa6bf18454. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4b6f18ec15fa431a4ad7cda366c67d81a574e2a5bfa339ef3f46b6aa6bf18454
SHA3-384 hash: 2592ca1f10c4a00217387e130f1c3d4792c53a8879438a11a2a8a10fddd5f34edd4de89cf7a82abc7889f4663bfea7c0
SHA1 hash: 26cf0c850739dbd4d800f67252f92cad1e2718cc
MD5 hash: 7df779cc46f36268ca780912e12e701f
humanhash: iowa-pip-helium-dakota
File name:DHL Details + Demurrage Charges.img
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2021-02-11 23:34:55 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:JqPntsvAEZi9701LTLzH/YjUx0pem8Mxtpn+nFzOPmlLpkYv0D4G/32IULjDaDqM:IYZH/LD/Ys0pePMVaznHfY4G/Vvq2a
TLSH 2165F1222758AF54E07C1B7B88B04820A3FDDE02AF22E64F7DEC35DC55B2FD86561646
Reporter cocaman
Tags:AgentTesla img


Avatar
cocaman
Malicious email (T1566.001)
From: "DHL Customer Service <cvn@snet.net>" (likely spoofed)
Received: "from snet.net (unknown [103.151.122.27]) "
Date: "11 Feb 2021 15:34:04 -0800"
Subject: "DHL - Pending delivery"
Attachment: "DHL Details + Demurrage Charges.img"

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-12 04:16:41 UTC
File Type:
Binary (Archive)
Extracted files:
47
AV detection:
12 of 47 (25.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 4b6f18ec15fa431a4ad7cda366c67d81a574e2a5bfa339ef3f46b6aa6bf18454

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments