MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35f13608341f1ac8abc7f356f741937585471c29d16d41b6237696e0bf789817. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 35f13608341f1ac8abc7f356f741937585471c29d16d41b6237696e0bf789817
SHA3-384 hash: e153e01688d909229f17bbce18fbc9141d9cf29c6906e431687c427b21c1c9ca4167de8148092768af33fddc2be69410
SHA1 hash: 9d9f40babc908fa0429bc640cf85defb19701ba3
MD5 hash: 450e4f7c8e164121d9b565dc4959efa9
humanhash: alaska-network-romeo-johnny
File name:Overdue soa 06 2020.pdf.zip
Download: download sample
Signature AgentTesla
File size:452'777 bytes
First seen:2020-07-02 06:36:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:5KjS01rg4hGEzFK1NZXd4GwOmBdY6hLfS0:IjS01rn/haMJdfz
TLSH 70A42311FAB399E227939214B0B66D0D79E08D4E590E0336FA315EE5B1F51AE17BCC8C
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 142-4-22-49.unifiedlayer.com
Sending IP: 142.4.22.49
From: accounts@mewah.com.my
Reply-To: accunts@mawah.com.my
Subject: Urgent Overdue statement of account
Attachment: Overdue soa 06 2020.pdf.zip (contains "Overdue soa 06 2020.pdf.exe")

AgentTesla SMTP exfil server:
smtp.ionos.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-07-02 06:38:07 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 35f13608341f1ac8abc7f356f741937585471c29d16d41b6237696e0bf789817

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments