MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a23d2e98ceda115b16ed7a19b50c822d03716aeb8eedcde8a88f63b70105613e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a23d2e98ceda115b16ed7a19b50c822d03716aeb8eedcde8a88f63b70105613e
SHA3-384 hash: 9cba9eb367fc4110dfa197a7b07922df4cda704a869600a857f3f87ce99952216ae1f44eef2dcab890440cfedd51ae74
SHA1 hash: 7f1c3972b6d812d48c2f046c3e8425a959a5777d
MD5 hash: f4a93244a6870862525d3e3203145b36
humanhash: lemon-missouri-quebec-oscar
File name:shipping doc_pdf.gz
Download: download sample
Signature AgentTesla
File size:253'800 bytes
First seen:2020-05-06 08:35:35 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:2cSFI/Np6PC/oAOObbKYJbdqgF9tdeW8nx:2c3/bybuuibgoKnx
TLSH AF4423E1F1D1ED0828A72C9A64CACCB937B4E582F75D0B7D8FE92AB01802D1575F6C19
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: qproxy1-pub.mail.unifiedlayer.com
Sending IP: 173.254.64.10
From: DHL Express || Logistic Partner <custormerservice@dhl.com>
Subject: DHL Express - E-Way Bill Report
Attachment: shipping doc_pdf.gz (contains "shipping doc_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-06 09:35:37 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz a23d2e98ceda115b16ed7a19b50c822d03716aeb8eedcde8a88f63b70105613e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments