MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f723675c1560d9dfc9b857a638f273b8446bb6028bf01b4a5906e21c9ef9740. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f723675c1560d9dfc9b857a638f273b8446bb6028bf01b4a5906e21c9ef9740
SHA3-384 hash: afe3d5aa23f412fb0e3e56a5177403aa75a2824b0bc1a2a209d2f3bc9f4726b18c34688ec35581a36715c9688bf5bfd7
SHA1 hash: 5516e9954fd54bd5f5a4b0001b9ecefb6bba32ae
MD5 hash: cd1ccdf7559d088f78fce7f84c1b5c9a
humanhash: jersey-item-eight-minnesota
File name:Shipping Document PLCI_PDF.gz
Download: download sample
Signature AgentTesla
File size:501'302 bytes
First seen:2020-06-15 12:00:57 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:3M0hENlyNWSbCLokeNgtAyHwxq19ky8QtZERYTAPdRXs:thENx5Ne87TPk/Y3Qls
TLSH FBB423FB7798A529F12EE97C895521E13C9B044772302C4EED3679F73189FA01B6862C
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 35-168-85-129.plesk.page
Sending IP: 35.168.85.129
From: DHL Global Mail Inc © <bdcare@dhl.com>
Reply-To: Costomer service <ricknicolas.aol@hotmail.com>
Subject: DHL Shipment Notification Ref ID: 44633179800
Attachment: Shipping Document PLCI_PDF.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.missingandfound.com.my:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-15 12:02:09 UTC
AV detection:
36 of 48 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 5f723675c1560d9dfc9b857a638f273b8446bb6028bf01b4a5906e21c9ef9740

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments