MALICIOUS — d391e5a02e6bb797cf003c6b66433a7c35db7adcd5009ad142719c9d81bb9fd5
MALICIOUS — d391e5a02e6bb797cf003c6b66433a7c35db7adcd5009ad142719c9d81bb9fd5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the AgentTesla family. 5 of 25 detection engines flagged it.
Identification
- SHA-256:
d391e5a02e6bb797cf003c6b66433a7c35db7adcd5009ad142719c9d81bb9fd5 - SHA-1:
d5475adecf956cce162ba9e9fd15ddf89015bc2f - MD5:
5e30f192ce4aaa1aabd0ae4e65fccf93 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
6144:O9tWQB624D/BNyIgfbpnlLDaJVG7n7XjisTyAm+GmP:O9wc6PBgIgjpnlLmJVG7n7XuSyAm+GmP - TLSH:
T1684710DA83BC1E56C4BCC0192F7EAD1B45FB59F9E5B93D9E052800710A5A33729309A2 - Submitted as: d391e5a02e6bb797cf003c6b66433a7c35db7adcd5009ad142719c9d81bb9fd5
- File type: pe · Size: 346520 bytes
- Verdict: malicious (91/100) · Family: AgentTesla
Detections (5 of 25 engines)
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:MSIL/AgentTesla.LJB!MTB
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): AgentTesla-FDDZ!5E30F192CE4A
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
Why this verdict
The malicious score of 91/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:MSIL/AgentTesla.LJB!MTB (rule
Trojan:MSIL/AgentTesla.LJB!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent (rule
Trojan.Agent) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged AgentTesla-FDDZ!5E30F192CE4A (rule
AgentTesla-FDDZ!5E30F192CE4A) - engine signal, weight 0.55, confidence 0.85 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 1.26.61.21 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
Embedded IP addresses
- 1.26.61.21
More AgentTesla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report