2020-11-06 - Possible Agent Tesla (AgentTesla)
2020-11-07 09:21:00 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:221 收藏

2020-11-06 - POSSIBLE AGENT TESLA (AGENTTESLA)

ASSOCIATED FILES

NOTES:

  • This one would not run on a VM, so I had to use a physical host.
  • This looks like Agent Tesla (AgentTesla), but the format for emails exfiltrating stolen victim data looks a little different than previous Agent Tesla samples I've investigated.
  • All zip archives on this site are password-protected with the standard password.  If you don't know it, see the "about" page of this website.

IMAGES


Shown above:  Screen shot of malspam pushing possible Agent Tesla.


Shown above:  Screen shot of attached spreadsheet with macro for the malware.


Shown above:  Traffic from the infection filtered in Wireshark, and the initial malware EXE saved to my infected lab host.


Shown above:  Malware persistent on my infected lab host.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2020/11/06/index.html
如有侵权请联系:admin#unsafe.sh