2020-11-06 - POSSIBLE AGENT TESLA (AGENTTESLA)
ASSOCIATED FILES
NOTES:
- This one would not run on a VM, so I had to use a physical host.
- This looks like Agent Tesla (AgentTesla), but the format for emails exfiltrating stolen victim data looks a little different than previous Agent Tesla samples I've investigated.
- All zip archives on this site are password-protected with the standard password. If you don't know it, see the "about" page of this website.
IMAGES
Shown above: Screen shot of malspam pushing possible Agent Tesla.
Shown above: Screen shot of attached spreadsheet with macro for the malware.
Shown above: Traffic from the infection filtered in Wireshark, and the initial malware EXE saved to my infected lab host.
Shown above: Malware persistent on my infected lab host.
Click here to return to the main page.
文章来源: https://www.malware-traffic-analysis.net/2020/11/06/index.html
如有侵权请联系:admin#unsafe.sh