VRad

#agenttesla_220822

Aug 23rd, 2022 (edited)
402
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.60 KB | None | 0 0
  1. #IOC #OptiData #VR #AgentTesla #tgz #EXE
  2.  
  3. https://pastebin.com/3JGCE5hN
  4.  
  5. previous_contact:
  6. 25/02/21 https://pastebin.com/YCVjJ8A6
  7. 10/02/21 https://pastebin.com/9JXvM5ix
  8. 07/12/20 https://pastebin.com/20AVUqZ6
  9. 04/12/20 https://pastebin.com/PYFMBfkg
  10. 15/06/20 https://pastebin.com/pma5MQAW
  11. 12/06/20 https://pastebin.com/SKNts0Es
  12. 29/10/19 https://pastebin.com/RinpBPvy
  13. 03/09/19 https://pastebin.com/zhJvDz8M
  14. 09/01/19 https://pastebin.com/MdDfZDdb
  15. 16/10/18 https://pastebin.com/d5DxTRrB
  16. 04/10/18 https://pastebin.com/JYShuXn4
  17. 11/10/18 https://pastebin.com/bkCSvJvM
  18.  
  19. FAQ:
  20. https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
  21.  
  22. attack_vector
  23. --------------
  24. email > URL to onedrive > TGZ > EXE > exfil to C2
  25.  
  26.  
  27. # # # # # # # #
  28. email_headers
  29. # # # # # # # #
  30.  
  31. Received: from server.globalyapi.net ([178.63.81.8])
  32. Received: from webmail.promyonetim.com.tr (localhost.localdomain [127.0.0.1])
  33. by server.globalyapi.net (Postfix) with ESMTPSA id DB39338616DF;
  34. Date: Mon, 22 Aug 2022 09:35:44 +0800
  35. From: Сьюзан Бойко <[email protected]>
  36. Subject: Новий ордер на купівлю #15060012
  37. User-Agent: Roundcube Webmail/1.4.13
  38. Message-ID: <[email protected]>
  39.  
  40.  
  41. # # # # # # # #
  42. files
  43. # # # # # # # #
  44.  
  45. SHA-256 fd170269fa86a676b7cb5979e9d86d933b1c42595042c1619ce6db85518b7c1c
  46. File name Новий ордер на купівлю.tgz [ GZIP ]
  47. File size 6.73 KB (6894 bytes)
  48.  
  49. SHA-256 e68d135a807112f6a645331dce18c395f6630c83c7b2e97ebc769a0bbbea1a96
  50. File name Новий ордер на купівлю.exe [ Generic CIL Executable (.NET, Mono, etc.) ]
  51. File size 73.50 KB (75264 bytes)
  52.  
  53. SHA-256 7ce8972b71a93178e1afbb9e66f74b80da79e69b044139f8b5e8e7939ea94d7c
  54. File name withoutstartup_Kimdoujs.png [ data ]
  55. File size 1.89 MB (1985544 bytes)
  56.  
  57.  
  58. # # # # # # # #
  59. activity
  60. # # # # # # # #
  61.  
  62. PL_SCR https://onedrive.live.com/download?cid=86BAE154236ED5D8&resid=86BAE154236ED5D8%21985&authkey=AJccsSHY3WHoX84
  63.  
  64.  
  65. C2 https://api.telegram.org/bot1884223853:AAFBJYLvV6hrzs4P4_W7nhkr0P8noC6MWKI/sendDocument
  66.  
  67.  
  68. netwrk
  69. --------------
  70. https://eglife100.com/loader/uploads/withoutstartup_Kimdoujs.png
  71. https://api.telegram.org/bot1884223853:AAFBJYLvV6hrzs4P4_W7nhkr0P8noC6MWKI/sendDocument
  72.  
  73.  
  74. comp
  75. --------------
  76. Новий ордер на купівлю.exe 67.211.214.194:443 [eglife100.com]
  77. InstallUtil.exe 149.154.167.220:443 [api.telegram.org]
  78.  
  79.  
  80. proc
  81. --------------
  82. "C:\Users\oper\AppData\Local\Temp\Новий ордер на купівлю.exe"
  83. "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANwAwAA==
  84. C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
  85. C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
  86.  
  87.  
  88. persist
  89. --------------
  90. n/a
  91.  
  92.  
  93. drop
  94. --------------
  95. C:\Users\oper\Desktop\Новий ордер на купівлю.exe
  96. C:\Windows\Microsoft.NET\Framework\v4.*\InstallUtil.exe
  97.  
  98.  
  99. # # # # # # # #
  100. VT & Intezer
  101. # # # # # # # #
  102.  
  103. Dropped files
  104. **************
  105. https://www.virustotal.com/gui/file/fd170269fa86a676b7cb5979e9d86d933b1c42595042c1619ce6db85518b7c1c/details
  106. https://www.virustotal.com/gui/file/e68d135a807112f6a645331dce18c395f6630c83c7b2e97ebc769a0bbbea1a96/details
  107. https://www.virustotal.com/gui/file/7ce8972b71a93178e1afbb9e66f74b80da79e69b044139f8b5e8e7939ea94d7c/details
  108. https://analyze.intezer.com/analyses/7a7a9497-1624-41c8-89a8-be712557cb3e
  109.  
  110.  
  111. VR
Add Comment
Please, Sign In to add comment