Click to jump to signature section
Source: 231210-01-AgentTesla-2eba02.exe | Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Port": "587", "Host": "mail.elec-qatar.com", "Username": "mohammed.abrar@elec-qatar.com", "Password": "MHabrar2019@#"} |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: 231210-01-AgentTesla-2eba02.exe, 00000001.00000002.2494896359.0000000002CC6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://mail.elec-qatar.com |
Source: 231210-01-AgentTesla-2eba02.exe | String found in binary or memory: https://account.dyn.com/ |
Source: 231210-01-AgentTesla-2eba02.exe, type: SAMPLE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 1.0.231210-01-AgentTesla-2eba02.exe.9b0000.0.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C49378 | 1_2_02C49378 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C44A98 | 1_2_02C44A98 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C43E80 | 1_2_02C43E80 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C4CFC8 | 1_2_02C4CFC8 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C49C00 | 1_2_02C49C00 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C441C8 | 1_2_02C441C8 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FBDD58 | 1_2_05FBDD58 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FBBD40 | 1_2_05FBBD40 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB3F80 | 1_2_05FB3F80 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB5720 | 1_2_05FB5720 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB0040 | 1_2_05FB0040 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB8BE0 | 1_2_05FB8BE0 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB9B28 | 1_2_05FB9B28 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB2B10 | 1_2_05FB2B10 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB5028 | 1_2_05FB5028 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_05FB3278 | 1_2_05FB3278 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Code function: 1_2_02C49BF8 | 1_2_02C49BF8 |
Source: 231210-01-AgentTesla-2eba02.exe, 00000001.00000000.1238173889.00000000009EE000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilename068524b8-d918-4107-9401-212dd26aaaa3.exe4 vs 231210-01-AgentTesla-2eba02.exe |
Source: 231210-01-AgentTesla-2eba02.exe, 00000001.00000002.2490949004.0000000000D89000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs 231210-01-AgentTesla-2eba02.exe |
Source: 231210-01-AgentTesla-2eba02.exe, 00000001.00000002.2491592427.0000000000E6E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs 231210-01-AgentTesla-2eba02.exe |
Source: 231210-01-AgentTesla-2eba02.exe | Binary or memory string: OriginalFilename068524b8-d918-4107-9401-212dd26aaaa3.exe4 vs 231210-01-AgentTesla-2eba02.exe |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: 231210-01-AgentTesla-2eba02.exe, type: SAMPLE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.0.231210-01-AgentTesla-2eba02.exe.9b0000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 231210-01-AgentTesla-2eba02.exe, jCzkkFGbiW.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, ZFYrnBYEI.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, TAIf.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, fMld7.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 231210-01-AgentTesla-2eba02.exe, jT3EMCHnL02.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, LyqEkh9QZ.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, tF0n0U.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe, tF0n0U.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 231210-01-AgentTesla-2eba02.exe | Binary string: ID: 0x{0:X}qSize of the SerializedPropertyStore is less than 8 ({0})/StoreSize: {0} (0x{0X})3\Device\LanmanRedirector\[Failed to retrieve system handle information. |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: 231210-01-AgentTesla-2eba02.exe | Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80% |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR |
Source: 231210-01-AgentTesla-2eba02.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Memory allocated: 1320000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Memory allocated: 2C70000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Memory allocated: 4C70000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -19369081277395017s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2232 | Thread sleep count: 1560 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2232 | Thread sleep count: 4111 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99653s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99532s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99407s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99282s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99157s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -99046s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98922s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98813s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98482s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98247s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -98103s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97516s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97407s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97282s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97157s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -97047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -96922s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -96813s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -96703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -96594s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -96469s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe TID: 2940 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Last function: Thread delayed |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Last function: Thread delayed |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99766 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99653 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99532 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99407 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99282 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99157 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 99046 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98922 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98813 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98703 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98593 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98482 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98360 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98247 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 98103 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97641 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97516 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97407 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97282 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97157 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 97047 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 96922 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 96813 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 96703 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 96594 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 96469 | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: 231210-01-AgentTesla-2eba02.exe, 00000001.00000002.2491592427.0000000000F0D000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll\Q6 |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: Yara match | File source: 231210-01-AgentTesla-2eba02.exe, type: SAMPLE |
Source: Yara match | File source: 1.0.231210-01-AgentTesla-2eba02.exe.9b0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000001.00000002.2494896359.0000000002CBE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000000.1238101496.00000000009B2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.2494896359.0000000002C71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: 231210-01-AgentTesla-2eba02.exe PID: 2692, type: MEMORYSTR |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles | Jump to behavior |
Source: C:\Users\user\Desktop\231210-01-AgentTesla-2eba02.exe | Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities | Jump to behavior |
Source: Yara match | File source: 231210-01-AgentTesla-2eba02.exe, type: SAMPLE |
Source: Yara match | File source: 1.0.231210-01-AgentTesla-2eba02.exe.9b0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000001.00000000.1238101496.00000000009B2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.2494896359.0000000002C71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: 231210-01-AgentTesla-2eba02.exe PID: 2692, type: MEMORYSTR |
Source: Yara match | File source: 231210-01-AgentTesla-2eba02.exe, type: SAMPLE |
Source: Yara match | File source: 1.0.231210-01-AgentTesla-2eba02.exe.9b0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000001.00000002.2494896359.0000000002CBE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000000.1238101496.00000000009B2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.2494896359.0000000002C71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: 231210-01-AgentTesla-2eba02.exe PID: 2692, type: MEMORYSTR |