MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 504c94554c7656c9ebc7044091c20562cc1ed853163baedc9714f05b2b8a273d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 504c94554c7656c9ebc7044091c20562cc1ed853163baedc9714f05b2b8a273d
SHA3-384 hash: 9113727e4da22df083875bf795eacf83d39a660192d28ad28eec8dd2c352fedf6383878aa27c78d191c0ab337d0ddd4a
SHA1 hash: 59484fa53d1781763a04837d2fcb3ebee7abfe2f
MD5 hash: daaee2aa29bf6ae3c0ff6ad0af20216c
humanhash: leopard-helium-apart-moon
File name:DHL Shipment Notification AWB Number 1480892346_PDF.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-10-19 10:01:14 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:e9EJ9wt2L2C1Iz0i1h4L95y/Id/SbNahcsbMM50:e4YC1Iz0ikjyQSbs6sg
TLSH A8458DB1EC996CDEC56A0675547984C1B9762BCB3B6C4E0D70BA72080E316D7B723E0B
Reporter abuse_ch
Tags:AgentTesla DHL img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: box.deliverystore.xyz
Sending IP: 192.236.162.161
From: DHL EXPRESS <dhl-noreply-dhl@deliverystore.xyz>
Subject: DHL Shipment Notification : 1480892346
Attachment: DHL Shipment Notification AWB Number 1480892346_PDF.img (contains "DHL Shipment Notification (AWB Number 1480892346)_PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-19 05:31:05 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 504c94554c7656c9ebc7044091c20562cc1ed853163baedc9714f05b2b8a273d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments