CLEAN — 274057577758e64eba0d9d58f319ae493ba188bfcccd7a92c9fa9300069bccf3
CLEAN — 274057577758e64eba0d9d58f319ae493ba188bfcccd7a92c9fa9300069bccf3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 5 of 55 detection engines flagged it.
Identification
- SHA-256:
274057577758e64eba0d9d58f319ae493ba188bfcccd7a92c9fa9300069bccf3 - SHA-1:
f825dae425242059da3a01ed8b24274b47314d7c - MD5:
d231db20bb2276fb787bc95930a34310 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:oYmYF5thbJGS5Q78iIXklWTFSYM7gt7u4BKF3TlFVbvxQeWxuOYD5PClFB3AyI8X:oSXbUSmwu4O/PCXB3dI8MzQxVIe - TLSH:
T12A48D85F8FAC1C64C8DD442E1ABF1EDB85EF646DA672710E1D3844325AAC9334A211B3 - Submitted as: 274057577758e64eba0d9d58f319ae493ba188bfcccd7a92c9fa9300069bccf3
- File type: pe · Size: 383384 bytes
- Verdict: clean (25/100)
Detections (5 of 55 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:MSIL/AgentTesla.LJB!MTB
- Emsisoft (Emergency Kit): Trojan.Generic.37572551
- Trellix Stinger (McAfee): AgentTesla-FDDZ!D231DB20BB22
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report