MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebf8ac1191de4896dab8380c706c61bf1369e9d52adee75b0811f326c1ad6a9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ebf8ac1191de4896dab8380c706c61bf1369e9d52adee75b0811f326c1ad6a9b
SHA3-384 hash: 955527e915083b5aad071b40c49edecef634e337a3ac14837823b4e048210a4d0f32b52a2ca32437fd0c9653a86f8687
SHA1 hash: 4f9010fdaef794185ea03384e4219edd5ff6851e
MD5 hash: e773a245ae3d00e78e13fd4c0028c583
humanhash: enemy-mountain-autumn-fruit
File name:SHIPPING DOCUMENT_pdf.rar
Download: download sample
Signature AgentTesla
File size:249'689 bytes
First seen:2020-08-11 14:14:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:d0wWeRPHaKKvOE1+70BT3t/rVB46lHSAdW448JDEI+b2:d0+9HaVvOE3BR/rVBVlHSAu8JDy2
TLSH 5C3423E4875D97B06F4D097B6DF1B1F14B319AF3A74E88B46EB43360E6160CA258887C
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: de.uitn.com
Sending IP: 144.76.245.34
From: DHL EXPRESS <CUSTOMERSERVICE@DHL.COM>
Reply-To: DHL EXPRESS <soomla6384@yahoo.com>
Subject: Ref: DHL_AWB #1008936572891
Attachment: SHIPPING DOCUMENT_pdf.rar (contains "SHIPPING DOCUMENT_pdf.exe")

AgentTesla SMTP exfil server:
mail.rulmeca.co:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-11 14:16:06 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar ebf8ac1191de4896dab8380c706c61bf1369e9d52adee75b0811f326c1ad6a9b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments