Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #AgentTesla #AgentTeslaV3 #TGZ
- https://pastebin.com/yTFWfN94
- previous_contact:
- 25/02/21 https://pastebin.com/YCVjJ8A6
- 10/02/21 https://pastebin.com/9JXvM5ix
- 07/12/20 https://pastebin.com/20AVUqZ6
- 04/12/20 https://pastebin.com/PYFMBfkg
- 15/06/20 https://pastebin.com/pma5MQAW
- 12/06/20 https://pastebin.com/SKNts0Es
- 29/10/19 https://pastebin.com/RinpBPvy
- 03/09/19 https://pastebin.com/zhJvDz8M
- 09/01/19 https://pastebin.com/MdDfZDdb
- 16/10/18 https://pastebin.com/d5DxTRrB
- 04/10/18 https://pastebin.com/JYShuXn4
- 11/10/18 https://pastebin.com/bkCSvJvM
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
- attack_vector
- --------------
- email > URL to onedrive > TGZ > EXE > !delay 3 min! > exfil to smtp.gmail.com:587
- email_headers
- --------------
- Received: from utopia1.vservers.es (utopia1.vservers.es [188.164.199.149])
- Received: from webmail.ingesal.es (localhost.localdomain [IPv6:::1])
- Date: Wed, 04 Aug 2021 05:02:37 +0200
- From: Оплата та виставлення рахунків Укрсиббанк <gullonnieto@ingesal.es>
- Subject: Підтвердження рахунків-фактур, сплачених у встановлений термін
- User-Agent: Roundcube Webmail/1.4.11
- X-Sender: gullonnieto@ingesal.es
- files
- --------------
- SHA-256 8018b63bffbfcea96953755d8a07df253bbca2b11c3350d4002ea9f281f60f12
- File name Заплачені рахунки-фактури.tgz [ gzip compressed data ]
- File size 647.74 KB (663285 bytes)
- SHA-256 ba064650e5c04853b071b9213fc1f6629ea1ddc226ac904a285b1eb3cf414e99
- File name Заплачені рахунки-фактури.exe [ .NET executable ]
- File size 795.00 KB (814080 bytes)
- activity
- **************
- PL_SCR https://onedrive.live.com/download?cid=268BF90C75B12557&resid=268BF90C75B12557%21121&authkey=AKR4nvAsgk1eHjc
- C2 [smtp.gmail.com] 172.217.218.108, 108.177.127.108
- netwrk
- --------------
- 1.1.1.1 Standard query 0xc545 A smtp.gmail.com
- 172.217.218.108 51451 → 587 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- comp
- --------------
- Заплачені рахунки-фактури.exe 3408 TCP 108.177.127.108 587 ESTABLISHED
- Заплачені рахунки-фактури.exe 2100 TCP 172.217.218.108 587 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\Заплачені рахунки-фактури.exe
- C:\Users\operator\Desktop\Заплачені рахунки-фактури.exe
- C:\Users\operator\Desktop\Заплачені рахунки-фактури.exe
- persist
- --------------
- n/a
- drop
- --------------
- n/a
- # # #
- VT details
- https://www.virustotal.com/gui/file/8018b63bffbfcea96953755d8a07df253bbca2b11c3350d4002ea9f281f60f12/details
- https://www.virustotal.com/gui/file/ba064650e5c04853b071b9213fc1f6629ea1ddc226ac904a285b1eb3cf414e99/details
- https://analyze.intezer.com/analyses/688bcd2d-3013-4f9f-823a-3f78edd27f1f
- VR
Add Comment
Please, Sign In to add comment