MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5dab7f36b85a45667c439bef17c9c42f716e169fa497bf555e01177b8d9ff83e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5dab7f36b85a45667c439bef17c9c42f716e169fa497bf555e01177b8d9ff83e
SHA3-384 hash: bfb966b7ac46efa9a25197456732dee8587f99b08a9f3fa49ba2b35914439bf8e0b4311fd6d9400f28d5d0fb947caa05
SHA1 hash: 0e1dd55650688f1d99d2e56d4ab8db2dc8efe331
MD5 hash: fb3fb964599c7f78c9b9b01643ef3750
humanhash: low-low-freddie-uniform
File name:TransportLabel_5669155074.rar
Download: download sample
Signature AgentTesla
File size:1'215'662 bytes
First seen:2020-05-04 20:38:10 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:VSHAAu9T8Egx1TPYcAw9bQXOSI4kf/k/uNblqL1nngF25mn:VSHJu9Yhx1kcAOZTlAnnfsn
TLSH 134533E41C79FFF3A5186E21D7512AF0E91B9BFB4521A3521122EA59890F8EC8CCDD31
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: qproxy2.mail.unifiedlayer.com
Sending IP: 69.89.16.161
From: donotreply@dhl.com
Subject: DHL Express Shipment Confirmation
Attachment: TransportLabel_5669155074.rar (contains "DHL.exe")

AgentTesla SMTP exfil server:
smtp.onlinexpertsales.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-05-05 04:03:16 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 5dab7f36b85a45667c439bef17c9c42f716e169fa497bf555e01177b8d9ff83e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments