MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ca3a2c5c6a40cc515242dfd7e5499fecb3b3b558e98439b62b7a5e1b1ffbf449. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | ca3a2c5c6a40cc515242dfd7e5499fecb3b3b558e98439b62b7a5e1b1ffbf449 |
|---|---|
| SHA3-384 hash: | 1994fdb89f8805629ebc5d2f5e34724611911673b1c75053476e0ae4ea8f78f352125bbbdbc15050813449be77c029ff |
| SHA1 hash: | 5b1bab71e4ab4641886f1825cc86b00519778a22 |
| MD5 hash: | 43f0a6e8e53ef6a946d4a7b1875a5c55 |
| humanhash: | earth-sink-avocado-fourteen |
| File name: | DHL Arrival Notification AWB invoice.iso |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 841'728 bytes |
| First seen: | 2020-07-21 07:45:32 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:7jD9fx7oqF/UEJoagGgxmaFZqcqhR1SYR3qACVEqxURCTj:7jD9ho9EcxhqcqhR1SYR3exURA |
| TLSH | 60053A3D3A86A405C83D06B280B455D16AB1B5473E21CB0F7DCA179CAF52BCF7F0666A |
| Reporter | |
| Tags: | AgentTesla DHL iso |
abuse_ch
Malspam distributing AgentTesla:HELO: slot0.alvindoprt.ml
Sending IP: 173.82.208.104
From: DHL Express <info@alvindoprt.ml>
Subject: DHL Arrival Notification : AWB/invoice
Attachment: DHL Arrival Notification AWB invoice.iso (contains "DHL Arrival Notification AWB invoice.exe")
AgentTesla SMTP exfil server:
smtp.yandex.ru:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-21 07:47:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legal
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.