MALICIOUS — c2008513a66cd25a1a2b0c745a21b63e2913b64beb83450f380a737f1fd4e1a5
MALICIOUS — c2008513a66cd25a1a2b0c745a21b63e2913b64beb83450f380a737f1fd4e1a5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Remcos family. 5 of 55 detection engines flagged it.
Identification
- SHA-256:
c2008513a66cd25a1a2b0c745a21b63e2913b64beb83450f380a737f1fd4e1a5 - SHA-1:
b47e97c828006177ae296bb036fa42527b027146 - MD5:
eb81f569307ca082670ab823e327d350 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:N0UGBGX2nnLt+RTFH4eFhxjF9nrwnrjdyo6eN:NtG+TFH4eHxjFBwnrj - TLSH:
T1F150AECD2868775CE2F23A7720B0B2FEDD5BB99D2CB93E8419805871215DB2B803615D - Submitted as: c2008513a66cd25a1a2b0c745a21b63e2913b64beb83450f380a737f1fd4e1a5
- File type: pe · Size: 797184 bytes
- Verdict: malicious (89/100) · Family: Remcos
Detections (5 of 55 engines)
- ClamAV (daily): Win.Dropper.Remcos-10026421-0
- Microsoft Defender: Trojan:MSIL/AgentTesla.DLM!MTB
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): AgentTesla-FDFG!EB81F569307C
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Agensla.gen
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Remcos-10026421-0 (rule
Win.Dropper.Remcos-10026421-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.codeproject.com/Articles/16009/A-Much-Easier-to-Use-ListView - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.codeproject.com/Articles/16009/A-Much-Easier-to-Use-ListView
Embedded domains
- www.codeproject.com
File paths
- N:\fKS
More Remcos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report