Statik Analiz — AgentTesla | ORTA | CVSS: 5.0

Dosya

SHA25612a0143bf4da5fdd8277f8f51dc6c5414b3cca94e58a00fef70ae07abe5cca8e
MD5e9b9c32602aaecc89225cbebbe78b340
Dosya12a0143bf4da5fdd8277f8f51dc6c5414b3cca94e58a00fef70ae07abe5cca8e.hta
Boyut37,073 byte
TürMicrosoft HTML Application (HTA), Unicode text, UTF-8 text, with very long lines (11155), with CRLF
Stringler96

IOC

SHA25612a0143bf4da5fdd8277f8f51dc6c5414b3cca94e58a00fef70ae07abe5cca8e
MD5e9b9c32602aaecc89225cbebbe78b340

AgentTesla — Profil du malware

AgentTesla .NET credential stealer. JS dropper @version 8.16.22. Sayısal obfuscation v6034. SMTP FTP HTTP C2.

Type de malware
Infostealer
Langage de programmation
.NET
Protocole C2
SMTP/FTP
Systèmes ciblés
Windows
Aussi connu sous (AKA)
Agent Tesla

Détails techniques

C#/.NET, SMTP/FTP/HTTP C2, GetAsyncKeyState keylogger, browser stealer (Chrome/Firefox/Edge), email client stealer, FTP stealer, VPN stealer, clipboard monitor, screenshot

Attribution / Acteur de la menace

Turkce konusulan gelistirici 'Turk Hack Team' ile iliskilendirilen ve Turkiye'den yonetildigi dusunulen platform. Pek cok farkli siber suc grubu musterisi bulunmaktadir.

Capacités et comportement

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

Serveurs C2 (8 serveurs enregistrés pour cette famille)

Adresse Type Port Protocole Statut Pays
digicert.com domain — TCP active —
stem.ru domain — TCP active —
digicert.com domain — TCP active —
system.io domain — TCP active —
dublincore.org domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
googleapis.com domain — TCP active —

Les adresses C2 proviennent uniquement d'échantillons de malwares vérifiés manuellement par l'équipe KEYDAL. Toute utilisation commerciale est interdite.

Tags
AgentTeslamalwarestatik-analizIOC