MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8989847eb07d683d713e9fec0158fe99e8622bc4210f62966d0d9d504389f25. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b8989847eb07d683d713e9fec0158fe99e8622bc4210f62966d0d9d504389f25
SHA3-384 hash: 62771955227b214c2f04ed86bfddf386cbd4d7e7c99c51e3c92d8b01c2253bd451347629e0de8e76576e3f984c5c5e02
SHA1 hash: b9a6e2e6f062b0a0f4c041be2bd19cb94c7bfa67
MD5 hash: 68e0bfd2e7520d2b86fa0f3616b8e539
humanhash: fish-hydrogen-asparagus-eighteen
File name:BL FOR SHIPMENT_doc.gz
Download: download sample
Signature AgentTesla
File size:703'099 bytes
First seen:2021-01-11 17:11:13 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:LYCeAdVKrvQMuJMiDErT5id98ET2O5z/ASWSwv/h79sR4xaF1u6J9ZiUp:MtAd4rtu48dHSO5z/A/9lEykV90Up
TLSH 16E423A66096224CF6BBC541BD6765CDCB65EECDF25C70BEF13A85A193EC2A408348D0
Reporter cocaman
Tags:gz


Avatar
cocaman
Malicious email (T1566.001)
From: "DHL EXPRESS INC<support@dhl.com>" (likely spoofed)
Received: "from dhl.com (unknown [103.145.252.28]) "
Date: "11 Jan 2021 09:01:09 -0800"
Subject: "DHL Invoice Notification for Account AWB 0867300"
Attachment: "BL FOR SHIPMENT_doc.gz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-11 17:12:06 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz b8989847eb07d683d713e9fec0158fe99e8622bc4210f62966d0d9d504389f25

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments