MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d14e0a744f5fa81fadc381637e173b465752db623c24dc98a75bd350da37e7d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d14e0a744f5fa81fadc381637e173b465752db623c24dc98a75bd350da37e7d7
SHA3-384 hash: 583fe82a00c9a1051f0ecd42b35945501434c038995fff6bf1becfde51767fbafade73ac178359943325f4a0787783c5
SHA1 hash: 8190ac1d2a57dafaff95b966ba1a62f00d2430fb
MD5 hash: f925daf782826be42d26fdd38a7403b7
humanhash: fish-neptune-timing-ohio
File name:Consignment Document PLBL Draft.img
Download: download sample
Signature AgentTesla
File size:761'856 bytes
First seen:2020-12-03 08:30:01 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:R2HV0CAO/8tsaZm/VGGNO332QplXGJi2o3TnCaR:R2HYBVm/MGillXe3szCa
TLSH 78F4F1F23144A59AE8F70DB5791525903DB3B96F99A0C28D78CC130E5BF33024A96FA7
Reporter abuse_ch
Tags:AgentTesla img TNT


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cloudhost-1555254.us-midwest-1.nxcli.net
Sending IP: 8.29.155.20
From: TNT EXPRESS® <service@tnt.com>
Subject: Consignment Notification: You have A Package With Us
Attachment: Consignment Document PLBL Draft.img (contains "Consignment Document PL&BL Draft.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-12-03 08:30:07 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img d14e0a744f5fa81fadc381637e173b465752db623c24dc98a75bd350da37e7d7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments