MALICIOUS — f84e52f5dc125e5d4f87b45cdb06f82374f19c2a3851313acb28932c2c9e32f5
MALICIOUS — f84e52f5dc125e5d4f87b45cdb06f82374f19c2a3851313acb28932c2c9e32f5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Agensla family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
f84e52f5dc125e5d4f87b45cdb06f82374f19c2a3851313acb28932c2c9e32f5 - SHA-1:
b9370df2c0e93f2da896fb11ba5e2f54d50bd22b - MD5:
bc2eadc6b001dd1517076ccd74d131f6 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:hRWzQhIikz1YedpdSgjaWTFH4eAqvCe8Uew6aGQUulbwqItKbfgTOXUOfxEG:Sx9pdSgjjTFH4efvCeWwrXUuiqdfgTA - TLSH:
T1FF50AECD15757759F3F13EB23498A2FEAD967A8E28F53FC409844C22261EB2B9131019 - Submitted as: f84e52f5dc125e5d4f87b45cdb06f82374f19c2a3851313acb28932c2c9e32f5
- File type: pe · Size: 770560 bytes
- Verdict: malicious (94/100) · Family: Agensla
Detections (5 of 52 engines)
- ClamAV (daily): Win.Dropper.Remcos-10026421-0
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Agensla.gen
- Microsoft Defender: Trojan:MSIL/AgentTesla.DLM!MTB
- Emsisoft (Emergency Kit): Trojan.Agent
- Trellix Stinger (McAfee): AgentTesla-FDFG!BC2EADC6B001
Why this verdict
The malicious score of 94/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Remcos-10026421-0 (rule
Win.Dropper.Remcos-10026421-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Trojan-PSW.MSIL.Agensla.gen (rule
HEUR:Trojan-PSW.MSIL.Agensla.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://www.codeproject.com/Articles/16009/A-Much-Easier-to-Use-ListView - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.codeproject.com/Articles/16009/A-Much-Easier-to-Use-ListView
Embedded domains
- www.codeproject.com
More Agensla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report