MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab9f01708b615e4449abaa49a47ec580ee3f6826e934a7df0c3f2cab31325714. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ab9f01708b615e4449abaa49a47ec580ee3f6826e934a7df0c3f2cab31325714
SHA3-384 hash: 8a3a4bf0ddc0fb9f0aa8053c85695562445b6eaf4b9fb4996dff0f4444dd3e3df4bdf4335f8e7a013b2098a45ae9a3cf
SHA1 hash: 5933288e60f672797d093bcc63b34e1a3a24bd5d
MD5 hash: 55f2e5eafea21e01a2039edbace0e7ed
humanhash: quebec-north-edward-white
File name:Shipment Airway Bill_pdf.gz
Download: download sample
Signature AgentTesla
File size:472'008 bytes
First seen:2020-06-03 09:10:09 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:852fQdcXCzM9w0SrGUt7sGXCetNVRbpVMTdcfUfpjeS41G:852IHM9wF7xs5eVZTM2fU9IU
TLSH 94A423D8E119B8B1D4F13E342BD34D9E583B12E68DA1BC1BC5D4A32148E1FD22E6352B
Reporter abuse_ch
Tags:AgentTesla DHL gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.vinylbannersprinting.co.uk
Sending IP: 217.174.249.10
From: DHL EXPRESS <worldwide@dhl.com>
Subject: DHL Express shipment per-alert!!
Attachment: Shipment Airway Bill_pdf.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 16:21:28 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz ab9f01708b615e4449abaa49a47ec580ee3f6826e934a7df0c3f2cab31325714

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments