General

  • Target

    c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe

  • Size

    1.1MB

  • Sample

    240705-b7j2essanf

  • MD5

    ccd55adce3f0b0885c8e5acc7df26c6a

  • SHA1

    81dc532f21c8be7217f5473b63a4ddde835d55e8

  • SHA256

    c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7

  • SHA512

    5380ddd16710a64f43560863d5a2a40b2e84111e0c1789796c2ac2e4302aeb0bfd003193f00c80d627c2b1fe6aea8c3bb098e3ce742f5db3a6d651668cd5a75f

  • SSDEEP

    24576:zAHnh+eWsN3skA4RV1Hom2KXMmHa2Flqny7gIG/ox15LgYn5:+h+ZkldoPK8Ya2KnsT158A

Malware Config

Targets

    • Target

      c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe

    • Size

      1.1MB

    • MD5

      ccd55adce3f0b0885c8e5acc7df26c6a

    • SHA1

      81dc532f21c8be7217f5473b63a4ddde835d55e8

    • SHA256

      c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7

    • SHA512

      5380ddd16710a64f43560863d5a2a40b2e84111e0c1789796c2ac2e4302aeb0bfd003193f00c80d627c2b1fe6aea8c3bb098e3ce742f5db3a6d651668cd5a75f

    • SSDEEP

      24576:zAHnh+eWsN3skA4RV1Hom2KXMmHa2Flqny7gIG/ox15LgYn5:+h+ZkldoPK8Ya2KnsT158A

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks