MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca3a2c5c6a40cc515242dfd7e5499fecb3b3b558e98439b62b7a5e1b1ffbf449. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ca3a2c5c6a40cc515242dfd7e5499fecb3b3b558e98439b62b7a5e1b1ffbf449
SHA3-384 hash: 1994fdb89f8805629ebc5d2f5e34724611911673b1c75053476e0ae4ea8f78f352125bbbdbc15050813449be77c029ff
SHA1 hash: 5b1bab71e4ab4641886f1825cc86b00519778a22
MD5 hash: 43f0a6e8e53ef6a946d4a7b1875a5c55
humanhash: earth-sink-avocado-fourteen
File name:DHL Arrival Notification AWB invoice.iso
Download: download sample
Signature AgentTesla
File size:841'728 bytes
First seen:2020-07-21 07:45:32 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:7jD9fx7oqF/UEJoagGgxmaFZqcqhR1SYR3qACVEqxURCTj:7jD9ho9EcxhqcqhR1SYR3exURA
TLSH 60053A3D3A86A405C83D06B280B455D16AB1B5473E21CB0F7DCA179CAF52BCF7F0666A
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.alvindoprt.ml
Sending IP: 173.82.208.104
From: DHL Express <info@alvindoprt.ml>
Subject: DHL Arrival Notification : AWB/invoice
Attachment: DHL Arrival Notification AWB invoice.iso (contains "DHL Arrival Notification AWB invoice.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-21 07:47:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso ca3a2c5c6a40cc515242dfd7e5499fecb3b3b558e98439b62b7a5e1b1ffbf449

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments