General

  • Target

    82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe

  • Size

    1.2MB

  • Sample

    240701-pmq6wsvejr

  • MD5

    158c5c0367c262694f3c44ae85b891b6

  • SHA1

    c8ae2619967b6fbf4962a57a34c614b7c6517b45

  • SHA256

    82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340

  • SHA512

    ef67d25306f175ab98e33f2730b2423fe20c433b1329d8c6c5812b428cb040dbb4965d8c59d5aa3a99a0e1afef54e0c918075768f6b3d2cf68119d1aa872d3ea

  • SSDEEP

    24576:rqDEvCTbMWu7rQYlBQcBiT6rprG8aHd/W1zVtAdczPe8:rTvC/MTQYxsWR7aHd/WFVpz

Malware Config

Targets

    • Target

      82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340.exe

    • Size

      1.2MB

    • MD5

      158c5c0367c262694f3c44ae85b891b6

    • SHA1

      c8ae2619967b6fbf4962a57a34c614b7c6517b45

    • SHA256

      82215185860a139b407ad688a9a83a05ef78a9af58ee96f575e8dba25b965340

    • SHA512

      ef67d25306f175ab98e33f2730b2423fe20c433b1329d8c6c5812b428cb040dbb4965d8c59d5aa3a99a0e1afef54e0c918075768f6b3d2cf68119d1aa872d3ea

    • SSDEEP

      24576:rqDEvCTbMWu7rQYlBQcBiT6rprG8aHd/W1zVtAdczPe8:rTvC/MTQYxsWR7aHd/WFVpz

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks