MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97b4faa4dc366412fff002072000a2a075c8ce15c19308a6b2e6244cdf9e160c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 97b4faa4dc366412fff002072000a2a075c8ce15c19308a6b2e6244cdf9e160c
SHA3-384 hash: f4ec21003e1ed50830df8dd518b3bdf4580ffedfb74b58dbf843d6db1fedaeb941d31db412015a83a61d39da09f3b0d0
SHA1 hash: 31f978c94319cf42737e9781caa85e02df0db940
MD5 hash: bb0e6f9781e5194967006b05ffc2bca7
humanhash: triple-cola-nevada-island
File name:DOH0003675550.pdf.cab
Download: download sample
Signature AgentTesla
File size:375'138 bytes
First seen:2020-11-18 12:17:10 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:ZtKUKEA7gZTGDssuF/9nv/egqjOp9K4qi2ip2p3u/kgy2OLegPQkEVXXJb:VBZaDsr/9nvWgL9Bt2ip2p4kgy2O5Qk+
TLSH 7B842377E35B373D5452E36A72237F430BAEBD3858809835F8024A7F065B6BAD8E4446
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: xwx0.319.suaon.ml
Sending IP: 139.59.250.122
From: Ali Al Faqir <info@319.suaon.ml>
Subject: ****PAYMENT REMINDER****
Attachment: DOH0003675550.pdf.cab (contains "DOH0003675550.pdf.exe")

AgentTesla SMTP exfil server:
smtp.fnsst.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-11-18 12:18:05 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 97b4faa4dc366412fff002072000a2a075c8ce15c19308a6b2e6244cdf9e160c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments