MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 17a7c2bf197cb5e0dd9ad96d0cb2625661d137eff971197af0251f2e7b18aa35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 17a7c2bf197cb5e0dd9ad96d0cb2625661d137eff971197af0251f2e7b18aa35
SHA3-384 hash: 3eec99a4c2566203997c3708bcc7abf2e8b9f22d9eeb14ea37afb8ccb2b273d2d29a2dfae46f005abaf53cad207b14dd
SHA1 hash: a776c3dc0576668a0a6fb0e9a7309b8cc0289ab4
MD5 hash: c65e13dd721dc2a35b2b75525c065b6a
humanhash: yellow-lima-march-blue
File name:Template- OWP.zip
Download: download sample
Signature AgentTesla
File size:296'306 bytes
First seen:2020-06-14 16:00:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:7At1r6qygAL+ipgKm3FOhDYci852dCpn/JJaTRZiJQDJfTv/Q:Mt1r6Ji6gKm3FONYci48Cp/3CQJSJr3Q
TLSH B154231F5412B8376AF74F8B401F639C8B95138E1633B9C8B4E78C35549B681BAB3C5A
Reporter abuse_ch
Tags:AgentTesla MailChannels zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: crocodile.birch.relay.mailchannels.net
Sending IP: 23.83.209.45
From: sales01@qweqew34.xyz
Subject: Re: Re: Template
Attachment: Template- OWP.zip (contains "Template- OWP.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Ursu
Status:
Malicious
First seen:
2020-06-14 16:02:04 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 17a7c2bf197cb5e0dd9ad96d0cb2625661d137eff971197af0251f2e7b18aa35

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments