General

  • Target

    95a66e3cc1aba9c377366c3084a950c3f7f39566f12afec355ffa01735cd2c4b

  • Size

    1.1MB

  • Sample

    240701-blkqts1grb

  • MD5

    cd226ded15c44dc931f84faf5a7a6e1f

  • SHA1

    48c4423323c8aa4dc89db2e5f52786a5f0b8a104

  • SHA256

    95a66e3cc1aba9c377366c3084a950c3f7f39566f12afec355ffa01735cd2c4b

  • SHA512

    36e7dead07ebd6d164b9392347b10fdffaef424a0d6027ff0b697ccef28c7c3524b7233c97173ceb69437ccf4c616c40f625c174f56b0b2e3be38495f036d68a

  • SSDEEP

    24576:5AHnh+eWsN3skA4RV1Hom2KXMmHavLA3oH8pBQ25:Ah+ZkldoPK8Yavk3os7

Malware Config

Extracted

Family

agenttesla

Credentials

Targets

    • Target

      95a66e3cc1aba9c377366c3084a950c3f7f39566f12afec355ffa01735cd2c4b

    • Size

      1.1MB

    • MD5

      cd226ded15c44dc931f84faf5a7a6e1f

    • SHA1

      48c4423323c8aa4dc89db2e5f52786a5f0b8a104

    • SHA256

      95a66e3cc1aba9c377366c3084a950c3f7f39566f12afec355ffa01735cd2c4b

    • SHA512

      36e7dead07ebd6d164b9392347b10fdffaef424a0d6027ff0b697ccef28c7c3524b7233c97173ceb69437ccf4c616c40f625c174f56b0b2e3be38495f036d68a

    • SSDEEP

      24576:5AHnh+eWsN3skA4RV1Hom2KXMmHavLA3oH8pBQ25:Ah+ZkldoPK8Yavk3os7

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks