MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 672efe599206140279ea2cccb9e646a5d031eaaf095d2ca7e2c1967fb0611ed7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 672efe599206140279ea2cccb9e646a5d031eaaf095d2ca7e2c1967fb0611ed7
SHA3-384 hash: d013bd7ec078cf23f30e104bd04c0815c4fde2d8fee965e8c694516f5b36ea9e44e81d8d1336de208b6d64615fdb9718
SHA1 hash: 9d0df3db593b3085e22309b090b25c3c7989b4eb
MD5 hash: f8b29834f577fa100797a3ef71c093f6
humanhash: juliet-south-lithium-spring
File name:Document Delivery [pptx].iso
Download: download sample
Signature AgentTesla
File size:550'912 bytes
First seen:2020-06-24 19:55:51 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:5xe6Nvn29zblsFaP+LAQ64kBHeczTBw799Sba1F8Q4t4LKnf:5TNvnUeFaPDv4CHeczY9ca1uH
TLSH 42C4012433E85B56C6AC877905F1214007BAB5AB6232E74F7E8CB29E1F63BD58512373
Reporter cocaman
Tags:AgentTesla iso


Avatar
cocaman
Malicious email
From: DHL-Document Shipping <info@logisticsexpressdelivery.com>
Received: from logisticsexpressdelivery.com (unknown [209.58.149.73])
Date: 24 Jun 2020 17:45:44 -0700
Subject: DHL-Consignment-Notification: You have a parcel.
Attachment: Document Delivery [pptx].iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 672efe599206140279ea2cccb9e646a5d031eaaf095d2ca7e2c1967fb0611ed7

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments