General
-
Target
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe
-
Size
1.2MB
-
Sample
240701-pmq6wsvejr
-
MD5
158c5c0367c262694f3c44ae85b891b6
-
SHA1
c8ae2619967b6fbf4962a57a34c614b7c6517b45
-
SHA256
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340
-
SHA512
ef67d25306f175ab98e33f2730b2423fe20c433b1329d8c6c5812b428cb040dbb4965d8c59d5aa3a99a0e1afef54e0c918075768f6b3d2cf68119d1aa872d3ea
-
SSDEEP
24576:rqDEvCTbMWu7rQYlBQcBiT6rprG8aHd/W1zVtAdczPe8:rTvC/MTQYxsWR7aHd/WFVpz
Static task
static1
Behavioral task
behavioral1
Sample
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe
-
Size
1.2MB
-
MD5
158c5c0367c262694f3c44ae85b891b6
-
SHA1
c8ae2619967b6fbf4962a57a34c614b7c6517b45
-
SHA256
82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340
-
SHA512
ef67d25306f175ab98e33f2730b2423fe20c433b1329d8c6c5812b428cb040dbb4965d8c59d5aa3a99a0e1afef54e0c918075768f6b3d2cf68119d1aa872d3ea
-
SSDEEP
24576:rqDEvCTbMWu7rQYlBQcBiT6rprG8aHd/W1zVtAdczPe8:rTvC/MTQYxsWR7aHd/WFVpz
Score10/10-
AgentTesla
Agent Tesla is a remote access tool (RAT) written in visual basic.
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-
Suspicious use of SetThreadContext
-