MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d31db65027a77e6102d33f6e84ff4190cf3c206730c7ab986101e91b1d66135d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d31db65027a77e6102d33f6e84ff4190cf3c206730c7ab986101e91b1d66135d
SHA3-384 hash: 3f50530627d688b072a4fc42e2dd18d37be33acb516b200c5d76d7d30aadc8c545575a27b276f99076c317650a73c75b
SHA1 hash: 0556ac38bcd83f2eb14be6df74408652a33d5485
MD5 hash: 0d7f416d7596759f75aaf21b8ebc2ae6
humanhash: quiet-colorado-kentucky-oregon
File name:DHL Details.lzh
Download: download sample
Signature AgentTesla
File size:1'021'444 bytes
First seen:2021-01-22 09:42:20 UTC
Last seen:2021-01-25 15:57:26 UTC
File type: lzh
MIME type:application/x-lzh-compressed
ssdeep 24576:a5tUGWiyKjS7Nn7OjyPa2nGVHdt5RnT8Y0A:a5Szid+NNP+1N8YX
TLSH A225337EB6ECBFD4F079A3B8AADD954AF540D4018AD3C44B4C2BE3BADD8C45061E9064
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
4
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-22 06:04:05 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

lzh d31db65027a77e6102d33f6e84ff4190cf3c206730c7ab986101e91b1d66135d

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments