General

  • Target

    939efef22639fa6851e6572551fe5ab08e9c5e165b3b998a5250938b510183a7

  • Size

    1.2MB

  • Sample

    240630-bffjxsvcjj

  • MD5

    ef98eeb9cfb0daacda53290f8cfe439b

  • SHA1

    f36528c2df8abb9528d424e452bcb14c22d43cd8

  • SHA256

    939efef22639fa6851e6572551fe5ab08e9c5e165b3b998a5250938b510183a7

  • SHA512

    2f79e2f2877c8427f9c9fd955db5b6d4e21cb69ff52be2eda9ed45b39ae4a6658eaaa87b018bf8ac7b4220bf4dc76b1d2237e46e383e03fb4ef55c9e97700b63

  • SSDEEP

    24576:pAHnh+eWsN3skA4RV1Hom2KXMmHathe2ppYZu15gKcGL5:wh+ZkldoPK8YanJpMMGKca

Malware Config

Extracted

Family

agenttesla

Credentials

Targets

    • Target

      939efef22639fa6851e6572551fe5ab08e9c5e165b3b998a5250938b510183a7

    • Size

      1.2MB

    • MD5

      ef98eeb9cfb0daacda53290f8cfe439b

    • SHA1

      f36528c2df8abb9528d424e452bcb14c22d43cd8

    • SHA256

      939efef22639fa6851e6572551fe5ab08e9c5e165b3b998a5250938b510183a7

    • SHA512

      2f79e2f2877c8427f9c9fd955db5b6d4e21cb69ff52be2eda9ed45b39ae4a6658eaaa87b018bf8ac7b4220bf4dc76b1d2237e46e383e03fb4ef55c9e97700b63

    • SSDEEP

      24576:pAHnh+eWsN3skA4RV1Hom2KXMmHathe2ppYZu15gKcGL5:wh+ZkldoPK8YanJpMMGKca

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks