MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 dc1668c8ed3324ec2f814a8ace07f8ba98411d307b84c1a5b9095d7e879403b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | dc1668c8ed3324ec2f814a8ace07f8ba98411d307b84c1a5b9095d7e879403b9 |
|---|---|
| SHA3-384 hash: | 03dab2f59d758934bc57f143d702207d49e28de219eec743de0f1cad27ecb7febc4c082851f6141b4eedc79ac14f4c86 |
| SHA1 hash: | 8c2b23a5ba9404468b12d0a2d162777b3fe057d2 |
| MD5 hash: | 367d3f329b46d9f7252824dc678f6245 |
| humanhash: | london-uncle-kansas-edward |
| File name: | BC.00012221-10122020_PDF.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 718'769 bytes |
| First seen: | 2020-10-12 19:31:32 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 12288:sL7esjM1qYNlXzplsPWkMIDjg500hG48IehvsV9UVrUIt5TTdQNHp/MmALuCdLU:I7esQ1q0DyQ0dzhCIrUsTONabdQ |
| TLSH | 7FE423C0F22E79590D63B893B0B72664516C58D2B7818BA1DEE1C7A8153B3770F367E8 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.forecastle-shipping.com
Sending IP: 202.93.27.5
From: sales support <sales.support@heintlogistics.com>
Subject: Fwd: [Urgent] (Payment made 8 October 2020 (15:00)
Attachment: BC.00012221-10122020_PDF.gz (contains "BC.00012221-10122020_PDF.exe")
AgentTesla SMTP exfil server:
smtp.yandex.ru:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-12 14:59:34 UTC
AV detection:
4 of 47 (8.51%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.