MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c978295cf0ee3f1e20829c2b924d1927c651c9ab4b8560b4601f5d50a2960082. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | c978295cf0ee3f1e20829c2b924d1927c651c9ab4b8560b4601f5d50a2960082 |
|---|---|
| SHA3-384 hash: | 147c41aa1805d80bf6fed6a28bf3852eb79a2db33b06a4fcf80c91df786756ae64fa2b01b6a8aafff1bba9eae3fde742 |
| SHA1 hash: | f3c95e8a5fcfe3665048b18358926bd9105a0e6f |
| MD5 hash: | d7e5f9ff632a9cc19a36e88990f561a9 |
| humanhash: | xray-white-violet-shade |
| File name: | Scan Copy_doc.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 712'715 bytes |
| First seen: | 2020-12-29 06:54:26 UTC |
| Last seen: | 2020-12-29 06:58:22 UTC |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:dKMVQUkZ2WYilE3SSkzjLTa6WsyDIoi63zSpezorbRBGqHlzu71eMO5uEBmF/Q:d/VsZHXASjjLNvmiQzSYkrbRBGGzuReb |
| TLSH | ECE4333DF9A6C6F2E1723F3350926EA890A8D0A71953D0D00B9DF0BA45766163336993 |
| Reporter | |
| Tags: | AgentTesla gz |
cocaman
Malicious email (T1566.001)From: "DHL EXPRESS INC<support@dhl.com>" (likely spoofed)
Received: "from dhl.com (unknown [103.145.252.28]) "
Date: "28 Dec 2020 14:59:45 -0800"
Subject: "DHL Invoice Notification for Account AWB 0867300"
Attachment: "Scan Copy_doc.gz"
Intelligence
File Origin
# of uploads :
2
# of downloads :
334
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-28 23:24:04 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 29 (62.07%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.