General
-
Target
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c.exe
-
Size
234KB
-
Sample
240701-phra4avbqm
-
MD5
375a7c8575a28440c4e4f0b72df2f759
-
SHA1
960eb458a3e68b9388bafe727e6365527e20d841
-
SHA256
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c
-
SHA512
bc90eb46030e730b88a79684c3e29024022dd9ad95b2d0e9249962195d26b95c4dff3f8b93008ddd7b0189cd9d5a7afd7e79ee6c1570080c7ea28f38e014a716
-
SSDEEP
3072:yenp+iGyuVYE6LbqV1tE7sEhad1GRzK5MXAa4x:yenp+iGyuVYE6Lbq5Ecd+zbAv
Behavioral task
behavioral1
Sample
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c.exe
Resource
win10v2004-20240508-en
Malware Config
Extracted
agenttesla
Protocol: smtp- Host:
mail.iaa-airferight.com - Port:
587 - Username:
[email protected] - Password:
webmaster - Email To:
[email protected]
Targets
-
-
Target
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c.exe
-
Size
234KB
-
MD5
375a7c8575a28440c4e4f0b72df2f759
-
SHA1
960eb458a3e68b9388bafe727e6365527e20d841
-
SHA256
cb4952b33305e97d86f398405b0bcd4bb59f61bfa16bf4f27be8a8dc2584208c
-
SHA512
bc90eb46030e730b88a79684c3e29024022dd9ad95b2d0e9249962195d26b95c4dff3f8b93008ddd7b0189cd9d5a7afd7e79ee6c1570080c7ea28f38e014a716
-
SSDEEP
3072:yenp+iGyuVYE6LbqV1tE7sEhad1GRzK5MXAa4x:yenp+iGyuVYE6Lbq5Ecd+zbAv
Score10/10-
AgentTesla
Agent Tesla is a remote access tool (RAT) written in visual basic.
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-