MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 17ebc79deead0045ee882e95d96aff6677284c5b73a0cf0b4d28ed243627a004. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 17ebc79deead0045ee882e95d96aff6677284c5b73a0cf0b4d28ed243627a004
SHA3-384 hash: 46f6e8deebbe2e626ebaaf2c8cfdb9c673c40d2419bea7e7d2ff425747b0ba23d8c0f18c403a0273a5a9e18fc80e8c07
SHA1 hash: 00cf9cd3699d1625945d80b76ca6a5506f2e6f05
MD5 hash: 52564fe1223a39034fdca7f720d36f73
humanhash: nuts-winter-hotel-bluebird
File name:fatture n. 3092.zip
Download: download sample
Signature AgentTesla
File size:635'772 bytes
First seen:2020-10-13 14:46:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:o72TuQV8k/x38VPuWUpuR7ygU8LEmfKNE/neTzWAj12FRbCtAxg9:/TuQV8kZMcW7yhfEfa1iOmxg9
TLSH 05D423A933D4EC7AFEDF8914E61146204D91C0E980E4788EA5DC4CF1C9E74AB671B3B9
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sv01.invisual.pt
Sending IP: 94.46.167.170
From: Marco Galimberti <info@movii.it>
Subject: RE: PAGAMENTO
Attachment: fatture n. 3092.zip (contains "fatture n. 3092.exe")

AgentTesla SMTP exfil server:
smtp.edichem.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-13 12:49:54 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 17ebc79deead0045ee882e95d96aff6677284c5b73a0cf0b4d28ed243627a004

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments