General

  • Target

    Purchase List VIXEN International 90349033 PDF.exe

  • Size

    1.0MB

  • Sample

    240701-gnk29s1dmn

  • MD5

    69f57046caa17d23cef9177ea3b8ebd6

  • SHA1

    3a87991d67897d59db87b82165fda11b807a3ffe

  • SHA256

    9f1106f2ccae0b0bec34ba75bfc0dbd38367d2e361ab2aebcbf261791925ca64

  • SHA512

    a135eaf1028033cb120c3f988f5b345701d6433e4c54b0b81f513cbab32b72f2ab727b8d532dc04ea7c303cd9a47a4cfb944c8372d8ebe60e0a78005dfb0b2d4

  • SSDEEP

    24576:oAHnh+eWsN3skA4RV1Hom2KXMmHasT/h2O740wPJ8IuW5:vh+ZkldoPK8YasT/AOpwZ

Malware Config

Extracted

Family

agenttesla

Credentials

Targets

    • Target

      Purchase List VIXEN International 90349033 PDF.exe

    • Size

      1.0MB

    • MD5

      69f57046caa17d23cef9177ea3b8ebd6

    • SHA1

      3a87991d67897d59db87b82165fda11b807a3ffe

    • SHA256

      9f1106f2ccae0b0bec34ba75bfc0dbd38367d2e361ab2aebcbf261791925ca64

    • SHA512

      a135eaf1028033cb120c3f988f5b345701d6433e4c54b0b81f513cbab32b72f2ab727b8d532dc04ea7c303cd9a47a4cfb944c8372d8ebe60e0a78005dfb0b2d4

    • SSDEEP

      24576:oAHnh+eWsN3skA4RV1Hom2KXMmHasT/h2O740wPJ8IuW5:vh+ZkldoPK8YasT/AOpwZ

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks