MALICIOUS — Win32.AgentTesla.exe
MALICIOUS — Win32.AgentTesla.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Msilheracles family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fbddaa077f3 - SHA-1:
9aa826795798948e8058e3ff1342d81d5d8ee4fa - MD5:
2b294b3499d1cce794badffc959b7618 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:5qIrEFD09leQEA49darfr3/2AbitnVYE96ltR:5AFD1A498H2D - TLSH:
T1AB4AD589352C0B73C36259E60574D28B8DE360A33FED262049437D76D712EDB58A2B36 - Submitted as: Win32.AgentTesla.exe
- File type: pe · Size: 460800 bytes
- Verdict: malicious (94/100) · Family: Msilheracles
Detections (4 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:MSIL/Shufab.A!bit
- Emsisoft (Emergency Kit): Gen:Variant.msilheracles.128405
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 8 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in tsk_766baf19a5 (pid 1032) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:MSIL/Shufab.A!bit (rule
Trojan:MSIL/Shufab.A!bit) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.msilheracles.128405 (rule
Gen:Variant.msilheracles.128405) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 6.9.1.5, 17.18.7.0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1221 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- desktop-hsgcbep
- www.bing.com
- config.edge.skype.com
- aefd.nelreports.net
- watson.events.data.microsoft.com
- g.live.com
- dns.msftncsi.com
- self.events.data.microsoft.com
- edge.microsoft.com
- www.msftncsi.com
- time.windows.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
- _dosvc._tcp.local
Dropped files
- 3ee8acf49be6d718f214e22396cca984b869e64fa82980246cadcbb7e2c79556 -
3ee8acf49be6d718f214e22396cca984b869e64fa82980246cadcbb7e2c79556 - d5ef8d781a43de391276e4c4dfbcb5a8f54417cb825da7283027b21376332654 -
d5ef8d781a43de391276e4c4dfbcb5a8f54417cb825da7283027b21376332654 - 9150c1f6a25bc5b4dec90461787be7739d4e621eba8fd8dbf8b2517f7da6d677 -
9150c1f6a25bc5b4dec90461787be7739d4e621eba8fd8dbf8b2517f7da6d677
Embedded domains
- aefd.nelreports.net
Embedded IP addresses
- 6.9.1.5
- 17.18.7.0
More Msilheracles samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report