TF-1859916
high
📛 Threat Title
AgendaCrypt: MD5 hash of a malware sample (payload) dd51094e4f4ac5bbb533a22156ae5050
Description
Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: AgendaCrypt (aliases: Agenda,Qilin). Confidence: 75. First seen: 2026-07-27 05:12:20 UTC. Reporter: TheRavenFile. Tags: agenda, qilin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
dd51094e4f4ac5bbb533a22156ae5050
IOC database
- Type
- hash_md5
- Value
dd51094e4f4ac5bbb533a22156ae5050- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- MD5 hash of a malware sample (payload) attributed to AgendaCrypt
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: AgendaCrypt (aliases: Agenda,Qilin). Confidence: 75. First seen: 2026-07-27 05:12:20 UTC. Reporter: TheRavenFile. Tags: agenda, qilin.
Remediations (10)
-
web:github.com
The Cybersight Security Malware Samples repository is a curated collection of malicious software specimens for cybersecurity research and analysis. This repository provides security professionals with real-world samples to study malware behavior, develop detection techniques, and enhance defensive strategies.
-
web:github.com
Malware - Hash -Database aims to provide a centralized collection of malware hashes for use in cybersecurity research, threat intelligence, and digital forensics. By maintaining a diverse set of hash types and regularly updating the repository, we aim to support professionals in identifying and analyzing malware threats effectively.
-
web:inventivehq.com
Free file hash checker & malicious hash lookup. Drag-drop a file to hash it in your browser, or bulk-check MD5 /SHA-1/SHA-256 hashes against malware databases — VirusTotal & MalwareBazaar links included.
-
web:threatfox.abuse.ch
AgendaCrypt IOC: 80dabe87dee2818816c1b8f79ddac79c ( md5_hash ) You are viewing the ThreatFox database entry for md5_hash 80dabe87dee2818816c1b8f79ddac79c.
-
web:threatfox.abuse.ch
AgendaCrypt IOC: a5d8608c6bb4874880db60edcd90bbc6 ( md5_hash ) You are viewing the ThreatFox database entry for md5_hash a5d8608c6bb4874880db60edcd90bbc6.
-
web:threatfox.abuse.ch
AgendaCrypt IOC: 4d5f56957db4b4eec9d87b64f8f5026b ( md5_hash ) You are viewing the ThreatFox database entry for md5_hash 4d5f56957db4b4eec9d87b64f8f5026b.
-
web:threatfox.abuse.ch
AgendaCrypt IOC: dd51094e4f4ac5bbb533a22156ae5050 ( md5_hash ) You are viewing the ThreatFox database entry for md5_hash dd51094e4f4ac5bbb533a22156ae5050 .
-
web:threatfox.abuse.ch
AgendaCrypt IOC: eb6fff4ee0f03ae5191f11570ff221c5 ( md5_hash ) You are viewing the ThreatFox database entry for md5_hash eb6fff4ee0f03ae5191f11570ff221c5.
-
web:www.malshare.com
The MalShare Project is a community driven public malware repository that works to provide free access to malware samples and tooling to the infomation security community.
-
web:www.virustotal.com
Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.