Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #AgentTesla #tgz #EXE
- https://pastebin.com/3JGCE5hN
- previous_contact:
- 25/02/21 https://pastebin.com/YCVjJ8A6
- 10/02/21 https://pastebin.com/9JXvM5ix
- 07/12/20 https://pastebin.com/20AVUqZ6
- 04/12/20 https://pastebin.com/PYFMBfkg
- 15/06/20 https://pastebin.com/pma5MQAW
- 12/06/20 https://pastebin.com/SKNts0Es
- 29/10/19 https://pastebin.com/RinpBPvy
- 03/09/19 https://pastebin.com/zhJvDz8M
- 09/01/19 https://pastebin.com/MdDfZDdb
- 16/10/18 https://pastebin.com/d5DxTRrB
- 04/10/18 https://pastebin.com/JYShuXn4
- 11/10/18 https://pastebin.com/bkCSvJvM
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
- attack_vector
- --------------
- email > URL to onedrive > TGZ > EXE > exfil to C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Received: from server.globalyapi.net ([178.63.81.8])
- Received: from webmail.promyonetim.com.tr (localhost.localdomain [127.0.0.1])
- by server.globalyapi.net (Postfix) with ESMTPSA id DB39338616DF;
- Date: Mon, 22 Aug 2022 09:35:44 +0800
- From: Сьюзан Бойко <gsabanoglu@promyonetim.com.tr>
- Subject: Новий ордер на купівлю #15060012
- User-Agent: Roundcube Webmail/1.4.13
- Message-ID: <fafa2c0675bca6e26c5e0e8165be9654@promyonetim.com.tr>
- X-Sender: gsabanoglu@promyonetim.com.tr
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 fd170269fa86a676b7cb5979e9d86d933b1c42595042c1619ce6db85518b7c1c
- File name Новий ордер на купівлю.tgz [ GZIP ]
- File size 6.73 KB (6894 bytes)
- SHA-256 e68d135a807112f6a645331dce18c395f6630c83c7b2e97ebc769a0bbbea1a96
- File name Новий ордер на купівлю.exe [ Generic CIL Executable (.NET, Mono, etc.) ]
- File size 73.50 KB (75264 bytes)
- SHA-256 7ce8972b71a93178e1afbb9e66f74b80da79e69b044139f8b5e8e7939ea94d7c
- File name withoutstartup_Kimdoujs.png [ data ]
- File size 1.89 MB (1985544 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR https://onedrive.live.com/download?cid=86BAE154236ED5D8&resid=86BAE154236ED5D8%21985&authkey=AJccsSHY3WHoX84
- C2 https://api.telegram.org/bot1884223853:AAFBJYLvV6hrzs4P4_W7nhkr0P8noC6MWKI/sendDocument
- netwrk
- --------------
- https://eglife100.com/loader/uploads/withoutstartup_Kimdoujs.png
- https://api.telegram.org/bot1884223853:AAFBJYLvV6hrzs4P4_W7nhkr0P8noC6MWKI/sendDocument
- comp
- --------------
- Новий ордер на купівлю.exe 67.211.214.194:443 [eglife100.com]
- InstallUtil.exe 149.154.167.220:443 [api.telegram.org]
- proc
- --------------
- "C:\Users\oper\AppData\Local\Temp\Новий ордер на купівлю.exe"
- "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANwAwAA==
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
- persist
- --------------
- n/a
- drop
- --------------
- C:\Users\oper\Desktop\Новий ордер на купівлю.exe
- C:\Windows\Microsoft.NET\Framework\v4.*\InstallUtil.exe
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- Dropped files
- **************
- https://www.virustotal.com/gui/file/fd170269fa86a676b7cb5979e9d86d933b1c42595042c1619ce6db85518b7c1c/details
- https://www.virustotal.com/gui/file/e68d135a807112f6a645331dce18c395f6630c83c7b2e97ebc769a0bbbea1a96/details
- https://www.virustotal.com/gui/file/7ce8972b71a93178e1afbb9e66f74b80da79e69b044139f8b5e8e7939ea94d7c/details
- https://analyze.intezer.com/analyses/7a7a9497-1624-41c8-89a8-be712557cb3e
- VR
Add Comment
Please, Sign In to add comment