General
-
Target
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe
-
Size
1.1MB
-
Sample
240705-b7j2essanf
-
MD5
ccd55adce3f0b0885c8e5acc7df26c6a
-
SHA1
81dc532f21c8be7217f5473b63a4ddde835d55e8
-
SHA256
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7
-
SHA512
5380ddd16710a64f43560863d5a2a40b2e84111e0c1789796c2ac2e4302aeb0bfd003193f00c80d627c2b1fe6aea8c3bb098e3ce742f5db3a6d651668cd5a75f
-
SSDEEP
24576:zAHnh+eWsN3skA4RV1Hom2KXMmHa2Flqny7gIG/ox15LgYn5:+h+ZkldoPK8Ya2KnsT158A
Static task
static1
Behavioral task
behavioral1
Sample
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe
Resource
win10v2004-20240704-en
Malware Config
Targets
-
-
Target
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7.exe
-
Size
1.1MB
-
MD5
ccd55adce3f0b0885c8e5acc7df26c6a
-
SHA1
81dc532f21c8be7217f5473b63a4ddde835d55e8
-
SHA256
c2e57fb2b8206bd9b5d05d8a9b0d2e78082dd303ee6364b288d568fcd48900f7
-
SHA512
5380ddd16710a64f43560863d5a2a40b2e84111e0c1789796c2ac2e4302aeb0bfd003193f00c80d627c2b1fe6aea8c3bb098e3ce742f5db3a6d651668cd5a75f
-
SSDEEP
24576:zAHnh+eWsN3skA4RV1Hom2KXMmHa2Flqny7gIG/ox15LgYn5:+h+ZkldoPK8Ya2KnsT158A
Score10/10-
AgentTesla
Agent Tesla is a remote access tool (RAT) written in visual basic.
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-
Suspicious use of SetThreadContext
-