MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8b5ff14477ccb87cf94d440539cd50fc061f1992ee32357f209ee70465103b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b8b5ff14477ccb87cf94d440539cd50fc061f1992ee32357f209ee70465103b0
SHA3-384 hash: d151e426021d72f1f4e868ba0cb861ad4ee9e98396037d4686ca038058467f592dddd5102635d51c681bd349dbc26c70
SHA1 hash: 13224016981fe1c7356cf8f59c660d42fce56d56
MD5 hash: 2d70e771ae35efb03b75a0532544789e
humanhash: monkey-ten-kentucky-september
File name:Covid-19 update.zip
Download: download sample
Signature AgentTesla
File size:539'177 bytes
First seen:2020-04-29 18:51:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:GiC3nLutvd+v+MwC4kqStyPbdw2w/6K++ZuVeCRW7bq/aMvXTuTB:GiCXLEV+v+7C4kV4Rwh/X9URo7bq/vvc
TLSH C0B423658A113ED816CB9E63B73EA7EDB3062450F3CD01135BF41FBD9AA90A33491E25
Reporter abuse_ch
Tags:AgentTesla COVID-19 DHL zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: outsmtp01.sadecehosting.com
Sending IP: 77.92.152.36
From: DHL Express China <China@dhl-news.com>
Subject: Covid-19 update from DHL Express
Attachment: Covid-19 update.zip (contains "biggy file.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 19:36:04 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
32 of 48 (66.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b8b5ff14477ccb87cf94d440539cd50fc061f1992ee32357f209ee70465103b0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments