MALICIOUS — 7529dc864be3d37b289dfbd8cbb76def6c217df172b5756deeea19abc2a90f5e
MALICIOUS — 7529dc864be3d37b289dfbd8cbb76def6c217df172b5756deeea19abc2a90f5e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the AgentTesla family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7529dc864be3d37b289dfbd8cbb76def6c217df172b5756deeea19abc2a90f5e - SHA-1:
609ae12813876e497b024306b59a583176877cdc - MD5:
0497db71e0a32d17fb2139424bdefbff - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
98304:ZnYy8FII8DXyXG6Wc9Uom7g9OB+1S2FZ3EHerKCDO:ZYy8FII8sZt9UomGVNZ3EHWrO - TLSH:
T1E661123CCEB1C2BFFFFB0697182249FE2165782C48A0645B105CBB04D51975726B1AAB - Submitted as: 7529dc864be3d37b289dfbd8cbb76def6c217df172b5756deeea19abc2a90f5e
- File type: pe · Size: 4080640 bytes
- Verdict: malicious (99/100) · Family: AgentTesla
Detections (4 of 55 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:R0SH
- ClamAV (daily): Win.Dropper.AgentTesla-9916533-0
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Dropper.AgentTesla-9916533-0 (rule
Win.Dropper.AgentTesla-9916533-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Trojan.MSIL.Agent.gen (rule
HEUR:Trojan.MSIL.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-sections:R0SH (rule
high-entropy-sections:R0SH) - engine signal, weight 0.35, confidence 0.70 - 1 behavioral detection(s) across 1 rule(s): Discovery: enumerates installed security software [low] (rule
tl-security-software-discovery) - dynamic signal, weight 0.20, confidence 0.90 - Packing/obfuscation: high-entropy-sections:R0SH - static signal, weight 0.25, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
1162 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- c0afa9176eb7a82d639d3ca20764ed4e7559c0951fa694a2d4b35d85cfd0a2fb -
c0afa9176eb7a82d639d3ca20764ed4e7559c0951fa694a2d4b35d85cfd0a2fb - cafe3625e3c7c5bb9764206e4627b006c3673a99124e0d300993b599257f6255 -
cafe3625e3c7c5bb9764206e4627b006c3673a99124e0d300993b599257f6255
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- i.xyz
- go.uk
- y3.ru
Embedded IP addresses
- 52.168.117.168
- 52.123.252.222
- 4.230.171.124
- 20.42.179.204
- 85.210.196.11
- 52.230.59.222
- 135.232.92.137
- 20.184.175.6
- 74.178.240.51
- 4.150.223.102
- 172.178.240.162
- 52.110.12.28
- 52.110.12.45
File paths
- V:\n8
- F:\a~
- n:\@7
More AgentTesla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report