MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b8989847eb07d683d713e9fec0158fe99e8622bc4210f62966d0d9d504389f25. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | b8989847eb07d683d713e9fec0158fe99e8622bc4210f62966d0d9d504389f25 |
|---|---|
| SHA3-384 hash: | 62771955227b214c2f04ed86bfddf386cbd4d7e7c99c51e3c92d8b01c2253bd451347629e0de8e76576e3f984c5c5e02 |
| SHA1 hash: | b9a6e2e6f062b0a0f4c041be2bd19cb94c7bfa67 |
| MD5 hash: | 68e0bfd2e7520d2b86fa0f3616b8e539 |
| humanhash: | fish-hydrogen-asparagus-eighteen |
| File name: | BL FOR SHIPMENT_doc.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 703'099 bytes |
| First seen: | 2021-01-11 17:11:13 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:LYCeAdVKrvQMuJMiDErT5id98ET2O5z/ASWSwv/h79sR4xaF1u6J9ZiUp:MtAd4rtu48dHSO5z/A/9lEykV90Up |
| TLSH | 16E423A66096224CF6BBC541BD6765CDCB65EECDF25C70BEF13A85A193EC2A408348D0 |
| Reporter | |
| Tags: | gz |
cocaman
Malicious email (T1566.001)From: "DHL EXPRESS INC<support@dhl.com>" (likely spoofed)
Received: "from dhl.com (unknown [103.145.252.28]) "
Date: "11 Jan 2021 09:01:09 -0800"
Subject: "DHL Invoice Notification for Account AWB 0867300"
Attachment: "BL FOR SHIPMENT_doc.gz"
Intelligence
File Origin
# of uploads :
1
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-11 17:12:06 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
8 of 46 (17.39%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.