MALICIOUS — 0f2b42e74b69b831569d55b2b450a1a840b9a6edd3a43abc953c87b7fc3392b5.bin
MALICIOUS — 0f2b42e74b69b831569d55b2b450a1a840b9a6edd3a43abc953c87b7fc3392b5.bin is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (71/100), attributed to the AgentTesla family. 2 of 23 detection engines flagged it.
Identification
- SHA-256:
0f2b42e74b69b831569d55b2b450a1a840b9a6edd3a43abc953c87b7fc3392b5 - SHA-1:
135c0038a29d2209d4333e3c02ec163fa3b6ddae - MD5:
b2f762bb14208360400afb6ead98cfca - ssdeep:
12288:aZaymIsFxMB7NQ6HhMzdPcLz9B2uxlZIDfbPt99oCfYWYwvdDQvlHOQC9ChzCIg0:gBKavuHR45MXfaLQT70NIfcNPcbPVvc - TLSH:
T1075EE97A168AF87B182717EE3A96290905F4D3F68002421C79D37EED6FDB58A9D05F00 - Submitted as: 0f2b42e74b69b831569d55b2b450a1a840b9a6edd3a43abc953c87b7fc3392b5.bin
- File type: script · Size: 3146182 bytes
- Verdict: malicious (71/100) · Family: AgentTesla
Source: MalShare · first seen 2026-08-03T13:32:28.563Z · SHA-256 verified
Detections (2 of 23 engines)
- Emsisoft (Emergency Kit): GT:JS.AgentTesla.666.2BA9EDD2
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 71/100 is the fusion of 3 weighted signals:
- Emsisoft (Emergency Kit) flagged GT:JS.AgentTesla.666.2BA9EDD2 (rule
GT:JS.AgentTesla.666.2BA9EDD2) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec, wmi, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
1022 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 10.240.0.255
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 149.154.167.99 NL · Amsterdam · AS62041 Telegram Messenger Network
- 224.0.0.22
- ff02::2
- ff02::1
- ff02::1:ff12:3456
- ff02::1:ff4c:1d1d
- 23.214.88.27
Dropped files
- tmp_tmp.vuybeXWIg2 -
21d6b8b86b906f6fe6b5def941f93772cc71c04bfa603499fdd633d50b187ed2
Embedded IP addresses
- 149.154.167.99
File paths
- C:\x5cTemp\x5c
More AgentTesla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report