SUSPICIOUS — f7031c9629528d862d53b1b2e7f882cffe26cd20d9577cae61241522b4f79d24
SUSPICIOUS — f7031c9629528d862d53b1b2e7f882cffe26cd20d9577cae61241522b4f79d24 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (49/100). 6 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f7031c9629528d862d53b1b2e7f882cffe26cd20d9577cae61241522b4f79d24 - SHA-1:
f50029277a15689d519daea58cb409cc93edfbe1 - MD5:
17f0aabb0c8a9db9759b3c125624bb2d - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:QdOP5WX2A/4hFjxF08M82+sc9mTt5Vb+7Vh1j:T/NCj82uSY - TLSH:
T13C4B62C9832C3D11CDA9887F83EA618EC393E25539F77DAD475862225C05E670AF12B1 - Submitted as: f7031c9629528d862d53b1b2e7f882cffe26cd20d9577cae61241522b4f79d24
- File type: pe · Size: 514968 bytes
- Verdict: suspicious (49/100)
Detections (6 of 55 engines)
- capa (capabilities): capability:execution/powershell
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Trojan:MSIL/AgentTesla.DLB!MTB
- Emsisoft (Emergency Kit): Gen:Variant.MSILHeracles.200455
- Trellix Stinger (McAfee): AgentTesla-FDCV!17F0AABB0C8A
- Kaspersky (KVRT): UDS:Trojan-Spy.MSIL.Stealer.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 49/100 is the fusion of 2 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://www.digicert.com/CPS0
Embedded domains
- www.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- cacerts.digicert.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report