MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c978295cf0ee3f1e20829c2b924d1927c651c9ab4b8560b4601f5d50a2960082. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c978295cf0ee3f1e20829c2b924d1927c651c9ab4b8560b4601f5d50a2960082
SHA3-384 hash: 147c41aa1805d80bf6fed6a28bf3852eb79a2db33b06a4fcf80c91df786756ae64fa2b01b6a8aafff1bba9eae3fde742
SHA1 hash: f3c95e8a5fcfe3665048b18358926bd9105a0e6f
MD5 hash: d7e5f9ff632a9cc19a36e88990f561a9
humanhash: xray-white-violet-shade
File name:Scan Copy_doc.gz
Download: download sample
Signature AgentTesla
File size:712'715 bytes
First seen:2020-12-29 06:54:26 UTC
Last seen:2020-12-29 06:58:22 UTC
File type: gz
MIME type:application/gzip
ssdeep 12288:dKMVQUkZ2WYilE3SSkzjLTa6WsyDIoi63zSpezorbRBGqHlzu71eMO5uEBmF/Q:d/VsZHXASjjLNvmiQzSYkrbRBGGzuReb
TLSH ECE4333DF9A6C6F2E1723F3350926EA890A8D0A71953D0D00B9DF0BA45766163336993
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email (T1566.001)
From: "DHL EXPRESS INC<support@dhl.com>" (likely spoofed)
Received: "from dhl.com (unknown [103.145.252.28]) "
Date: "28 Dec 2020 14:59:45 -0800"
Subject: "DHL Invoice Notification for Account AWB 0867300"
Attachment: "Scan Copy_doc.gz"

Intelligence


File Origin
# of uploads :
2
# of downloads :
334
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-28 23:24:04 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz c978295cf0ee3f1e20829c2b924d1927c651c9ab4b8560b4601f5d50a2960082

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments