MALICIOUS — 866c117c82fa9a7a147d5697ba16f9ed3be1657892e0cdd19ea2593867b4317a
MALICIOUS — 866c117c82fa9a7a147d5697ba16f9ed3be1657892e0cdd19ea2593867b4317a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the AgentTesla family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
866c117c82fa9a7a147d5697ba16f9ed3be1657892e0cdd19ea2593867b4317a - SHA-1:
e7141b64f67a248199bc7373637b2180621d0ff3 - MD5:
c3560ba5b5f3e9163b12680b8d745253 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:aIptJOUTCi2FuYEsDg/BO9V7ALCUiPHSKM4lm4EErYSBM:h745FueU/BUV7ALCXPRACM - TLSH:
T1A24801D6EBBC9E64CDDC002F02BE0D5B85CB44ED9472712F092C8A794E6863B46255B3 - Submitted as: 866c117c82fa9a7a147d5697ba16f9ed3be1657892e0cdd19ea2593867b4317a
- File type: pe · Size: 377240 bytes
- Verdict: malicious (89/100) · Family: AgentTesla
Detections (5 of 52 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:MSIL/AgentTesla.LJB!MTB
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): AgentTesla-FDDZ!C3560BA5B5F3
- Kaspersky (KVRT): UDS:Trojan-PSW.MSIL.Reline.gen
Why this verdict
The malicious score of 89/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:MSIL/AgentTesla.LJB!MTB (rule
Trojan:MSIL/AgentTesla.LJB!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent (rule
Trojan.Agent) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged AgentTesla-FDDZ!C3560BA5B5F3 (rule
AgentTesla-FDDZ!C3560BA5B5F3) - engine signal, weight 0.55, confidence 0.85 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
More AgentTesla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report