Windows
Analysis Report
Global e-Banking Payment Advice 000000164.exe
Overview
General Information
Detection
AgentTesla
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Yara detected AgentTesla
Yara detected AntiVM3
.NET source code contains potential unpacker
Contains functionality to log keystrokes (.Net Source)
Drops VBS files to the startup folder
Encrypted powershell cmdline option found
Initial sample is a PE file and has a suspicious name
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: WScript or CScript Dropper
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Uses ipconfig to lookup or modify the Windows network settings
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Execution of Powershell with Base64
Sigma detected: Suspicious Outbound SMTP Connections
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara detected Credential Stealer
Yara signature match
Classification
- System is w10x64
Global e-Banking Payment Advice 000000164.exe (PID: 1740 cmdline:
"C:\Users\ user\Deskt op\Global e-Banking Payment Ad vice 00000 0164.exe" MD5: 182B367B8F111C09A11875F547E6A746) cmd.exe (PID: 752 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /release MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 4992 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 604 cmdline:
ipconfig / release MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB) powershell.exe (PID: 7404 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -enc QQBkA GQALQBNAHA AUAByAGUAZ gBlAHIAZQB uAGMAZQAgA C0ARQB4AGM AbAB1AHMAa QBvAG4AUAB hAHQAaAAgA EMAOgBcAFU AcwBlAHIAc wBcAGUAbgB nAGkAbgBlA GUAcgBcAEQ AZQBzAGsAd ABvAHAAXAB HAGwAbwBiA GEAbAAgAGU ALQBCAGEAb gBrAGkAbgB nACAAUABhA HkAbQBlAG4 AdAAgAEEAZ AB2AGkAYwB lACAAMAAwA DAAMAAwADA AMQA2ADQAL gBlAHgAZQA 7ACAAQQBkA GQALQBNAHA AUAByAGUAZ gBlAHIAZQB uAGMAZQAgA C0ARQB4AGM AbAB1AHMAa QBvAG4AUAB yAG8AYwBlA HMAcwAgAEM AOgBcAFUAc wBlAHIAcwB cAGUAbgBnA GkAbgBlAGU AcgBcAEQAZ QBzAGsAdAB vAHAAXABHA GwAbwBiAGE AbAAgAGUAL QBCAGEAbgB rAGkAbgBnA CAAUABhAHk AbQBlAG4Ad AAgAEEAZAB 2AGkAYwBlA CAAMAAwADA AMAAwADAAM QA2ADQALgB lAHgAZQA7A EEAZABkAC0 ATQBwAFAAc gBlAGYAZQB yAGUAbgBjA GUAIAAtAEU AeABjAGwAd QBzAGkAbwB uAFAAYQB0A GgAIABDADo AXABVAHMAZ QByAHMAXAB lAG4AZwBpA G4AZQBlAHI AXABBAHAAc ABEAGEAdAB hAFwAUgBvA GEAbQBpAG4 AZwBcAHAAY QBnAGUALgB lAHgAZQA7A CAAQQBkAGQ ALQBNAHAAU AByAGUAZgB lAHIAZQBuA GMAZQAgAC0 ARQB4AGMAb AB1AHMAaQB vAG4AUAByA G8AYwBlAHM AcwAgAEMAO gBcAFUAcwB lAHIAcwBcA GUAbgBnAGk AbgBlAGUAc gBcAEEAcAB wAEQAYQB0A GEAXABSAG8 AYQBtAGkAb gBnAFwAcAB hAGcAZQAuA GUAeABlAA= = MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) conhost.exe (PID: 7412 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) WmiPrvSE.exe (PID: 7580 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) InstallUtil.exe (PID: 7684 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57) cmd.exe (PID: 7708 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /renew MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 7720 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 7788 cmdline:
ipconfig / renew MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB)
wscript.exe (PID: 7888 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\Micro soft\Windo ws\Start M enu\Progra ms\Startup \page.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) page.exe (PID: 7940 cmdline:
"C:\Users\ user\AppDa ta\Roaming \page.exe" MD5: 182B367B8F111C09A11875F547E6A746) cmd.exe (PID: 8044 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /release MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 8052 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 8088 cmdline:
ipconfig / release MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB) InstallUtil.exe (PID: 8148 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57) cmd.exe (PID: 8180 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /renew MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 8188 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 1796 cmdline:
ipconfig / renew MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "SMTP", "Port": "25", "Host": "mail.iaa-airferight.com", "Username": "admin@iaa-airferight.com", "Password": "manlikeyou88"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
Click to see the 26 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
Click to see the 10 entries |
System Summary |
---|
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |