MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 514f576817142de8b78f2d37a26782bb6b4f11964b41d89eee9993ea37ea303e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 514f576817142de8b78f2d37a26782bb6b4f11964b41d89eee9993ea37ea303e
SHA3-384 hash: ca795e15779252b5a6a905fd504ba542f8c1b66fcbd1b5b9ddb60df43ceb30f3e922c426f36f1dcf69f858fffc2b9805
SHA1 hash: 353353a1eb54e03785cb5ce7f24467e99ac5dbf5
MD5 hash: 5e50b09ca984edd995cfc7f4d485f0f1
humanhash: uniform-thirteen-violet-texas
File name:Resibo ng DHL 8897209547, pdf.iso
Download: download sample
Signature AgentTesla
File size:659'456 bytes
First seen:2020-06-10 06:16:58 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:A7AuxSsm/3DgFvFsY1UTLraEIuBh4aqiFKveMn8a4p4kLv6uxGwWC5Qaux+ZAjp6:8rSTkFGz/raibnYYaul6uxG
TLSH CAE4AE9C365076DFC827CD779AA81C64AA207477471BD213A04B19ED9B0EADBCF112E3
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.ancleald.com
Sending IP: 45.95.169.157
From: DHL Express Cargo <delivery@dhl.com>
Subject: Ang paghahatid ng kargamento ng DHL
Attachment: Resibo ng DHL 8897209547, pdf.iso (contains "Resibo ng DHL 8897209547, pdf.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.Remcos
Status:
Malicious
First seen:
2020-06-10 06:18:04 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 514f576817142de8b78f2d37a26782bb6b4f11964b41d89eee9993ea37ea303e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments