MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae6b112a7dd4802d1229d529358e4db7dc6053cdd2c5bb845a937382791fa9c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: ae6b112a7dd4802d1229d529358e4db7dc6053cdd2c5bb845a937382791fa9c1
SHA3-384 hash: 83b896e8d8ad4b541524ee6769ea0acd9a1f69da032510708f1bb8bdf6fef9a9b26686dba49eb8f2649255d3d206e371
SHA1 hash: e21d0b14039633b775798e347f10883c2cec91eb
MD5 hash: e97c55334a2138f8c754df13d021a122
humanhash: wyoming-massachusetts-artist-early
File name:DHL&NBSP Reference ID 54787654.Z
Download: download sample
Signature AgentTesla
File size:400'113 bytes
First seen:2020-03-16 10:11:14 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:IJ9+Bbjt9rp6GKTTcwz0QOiX8mES8EFpV:asjt9rbwAdiiSNj
TLSH 2D8423F6B26754C18CEEE25B8971BA99A66EB18E94C1F0B04B000381DFF5DB277B5341
Reporter cocaman
Tags:AgentTesla z

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Autorun
Status:
Malicious
First seen:
2020-03-16 10:12:34 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z ae6b112a7dd4802d1229d529358e4db7dc6053cdd2c5bb845a937382791fa9c1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
Corsin Camichel commented on 2020-03-16 10:11:41 UTC

email subject: DHL INTERNATIONAL SHIPPING - COMMERCIAL INVOICE, CUSTOMS DUTY AND TAX DECLARATION - Reference ID 43419828