MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ebf8ac1191de4896dab8380c706c61bf1369e9d52adee75b0811f326c1ad6a9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | ebf8ac1191de4896dab8380c706c61bf1369e9d52adee75b0811f326c1ad6a9b |
|---|---|
| SHA3-384 hash: | 955527e915083b5aad071b40c49edecef634e337a3ac14837823b4e048210a4d0f32b52a2ca32437fd0c9653a86f8687 |
| SHA1 hash: | 4f9010fdaef794185ea03384e4219edd5ff6851e |
| MD5 hash: | e773a245ae3d00e78e13fd4c0028c583 |
| humanhash: | enemy-mountain-autumn-fruit |
| File name: | SHIPPING DOCUMENT_pdf.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 249'689 bytes |
| First seen: | 2020-08-11 14:14:12 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:d0wWeRPHaKKvOE1+70BT3t/rVB46lHSAdW448JDEI+b2:d0+9HaVvOE3BR/rVBVlHSAu8JDy2 |
| TLSH | 5C3423E4875D97B06F4D097B6DF1B1F14B319AF3A74E88B46EB43360E6160CA258887C |
| Reporter | |
| Tags: | AgentTesla DHL rar |
abuse_ch
Malspam distributing AgentTesla:HELO: de.uitn.com
Sending IP: 144.76.245.34
From: DHL EXPRESS <CUSTOMERSERVICE@DHL.COM>
Reply-To: DHL EXPRESS <soomla6384@yahoo.com>
Subject: Ref: DHL_AWB #1008936572891
Attachment: SHIPPING DOCUMENT_pdf.rar (contains "SHIPPING DOCUMENT_pdf.exe")
AgentTesla SMTP exfil server:
mail.rulmeca.co:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-11 14:16:06 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.