MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f56e424ca11fb6f85a7ff9b9f2d47b9f1eb92cbd0f46c959c504cfcad988073. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4f56e424ca11fb6f85a7ff9b9f2d47b9f1eb92cbd0f46c959c504cfcad988073
SHA3-384 hash: 51f247cf0207f191933bf3e46d9028b48c2b251b381ef75e9b9aec2bcf418c9ef9d059e9c9cb856b4563585943622c42
SHA1 hash: a3637379524e49884061208c8102b97ec88da3a3
MD5 hash: 929e01bf6ead1a4cac5e77c33dedd48b
humanhash: music-artist-north-robert
File name:DHL 517201602 image002.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-01 14:14:15 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:gqdEjJnPMEXqleHPjbpCPPhkSKpFqxwZnbg1GhDBFi:gRjVXUajSiSIquZbMGhVF
TLSH DF45D06E05A85A2FE6EE05FCC0689F40C3F1E457B2D3F74D99D841BC0A82746DDA25A3
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dhl.com
Sending IP: 176.123.7.98
From: DANZAS Communication (DHL AE) <diwakar.jha@dhl.com>
Subject: //Pre-Alert Docs// MAWB #157-5961 7552,HAWB
Attachment: DHL 517201602 image002.img (contains "DHL 517201602 image002.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-01 10:51:18 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 4f56e424ca11fb6f85a7ff9b9f2d47b9f1eb92cbd0f46c959c504cfcad988073

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments