MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc9e3a734e70c0f91b7d22bf4466d0fffc68854c72e0fef9e0c7a8fbd0e60c4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: bc9e3a734e70c0f91b7d22bf4466d0fffc68854c72e0fef9e0c7a8fbd0e60c4f
SHA3-384 hash: b84d619e6a53a2ebfca493f0dd95669890499a9ba4e1ddf18d6eb848f5c395b344c954275e379d6bfa292fef643aa376
SHA1 hash: fb3bdf90ca26d465b142fb60089b8f0d240f7609
MD5 hash: b8fcb7ff0a68a6613295726218ea3359
humanhash: juliet-winner-six-alabama
File name:DHL EXPRESS DELIVERY INVOICE.ace
Download: download sample
Signature AgentTesla
File size:412'752 bytes
First seen:2020-10-26 06:48:29 UTC
Last seen:Never
File type: ace
MIME type:application/octet-stream
ssdeep 6144:e3ibE781gQF/jUA7981PYv2jAe2FZYoOxTR351UsawV5jmKLT1WGv/+hK7M:e3V81gQFrURV/2FsxF35Cc3CqvO5
TLSH AB94231BB465040F1B7FBD6DA57AC23722C7783072253E8344C467B776A02A1B6673B9
Reporter cocaman
Tags:ace


Avatar
cocaman
Malicious email (T1566.001)
From: "DHL Express <dhl@315.xoron.ml>"
Received: "from postfix-inbound-13.inbound.mailchannels.net (inbound-egress-6.mailchannels.net [199.10.31.238]) "
Date: "Sun, 25 Oct 2020 22:28:06 -0700"
Subject: "DHL Shipment Notification"
Attachment: "DHL EXPRESS DELIVERY INVOICE.ace"

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-26 02:04:58 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
21 of 45 (46.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

ace bc9e3a734e70c0f91b7d22bf4466d0fffc68854c72e0fef9e0c7a8fbd0e60c4f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments