MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc1668c8ed3324ec2f814a8ace07f8ba98411d307b84c1a5b9095d7e879403b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc1668c8ed3324ec2f814a8ace07f8ba98411d307b84c1a5b9095d7e879403b9
SHA3-384 hash: 03dab2f59d758934bc57f143d702207d49e28de219eec743de0f1cad27ecb7febc4c082851f6141b4eedc79ac14f4c86
SHA1 hash: 8c2b23a5ba9404468b12d0a2d162777b3fe057d2
MD5 hash: 367d3f329b46d9f7252824dc678f6245
humanhash: london-uncle-kansas-edward
File name:BC.00012221-10122020_PDF.gz
Download: download sample
Signature AgentTesla
File size:718'769 bytes
First seen:2020-10-12 19:31:32 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:sL7esjM1qYNlXzplsPWkMIDjg500hG48IehvsV9UVrUIt5TTdQNHp/MmALuCdLU:I7esQ1q0DyQ0dzhCIrUsTONabdQ
TLSH 7FE423C0F22E79590D63B893B0B72664516C58D2B7818BA1DEE1C7A8153B3770F367E8
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.forecastle-shipping.com
Sending IP: 202.93.27.5
From: sales support <sales.support@heintlogistics.com>
Subject: Fwd: [Urgent] (Payment made 8 October 2020 (15:00)
Attachment: BC.00012221-10122020_PDF.gz (contains "BC.00012221-10122020_PDF.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-12 14:59:34 UTC
AV detection:
4 of 47 (8.51%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz dc1668c8ed3324ec2f814a8ace07f8ba98411d307b84c1a5b9095d7e879403b9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments