00000001.00000002.543325516.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.543325516.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.543325516.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x30184:$a13: get_DnsResolver
- 0x2e986:$a20: get_LastAccessed
- 0x30b16:$a27: set_InternalServerPort
- 0x30e32:$a30: set_GuidMasterKey
- 0x2ea8d:$a33: get_Clipboard
- 0x2ea9b:$a34: get_Keyboard
- 0x2fdb7:$a35: get_ShiftKeyDown
- 0x2fdc8:$a36: get_AltKeyDown
- 0x2eaa8:$a37: get_Password
- 0x2f55e:$a38: get_PasswordHash
- 0x30584:$a39: get_DefaultCredentials
|
00000000.00000002.343398236.00000000028F2000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000000.00000002.346179647.0000000002BC0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000001.00000002.545362105.0000000003D9F000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.545362105.0000000003D9F000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.545362105.0000000003D9F000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000001.00000002.545362105.0000000003D9F000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x30bd6:$a13: get_DnsResolver
- 0x654ac:$a13: get_DnsResolver
- 0x2f3d8:$a20: get_LastAccessed
- 0x63cae:$a20: get_LastAccessed
- 0x31568:$a27: set_InternalServerPort
- 0x65e3e:$a27: set_InternalServerPort
- 0x31884:$a30: set_GuidMasterKey
- 0x6615a:$a30: set_GuidMasterKey
- 0x2f4df:$a33: get_Clipboard
- 0x63db5:$a33: get_Clipboard
- 0x2f4ed:$a34: get_Keyboard
- 0x63dc3:$a34: get_Keyboard
- 0x30809:$a35: get_ShiftKeyDown
- 0x650df:$a35: get_ShiftKeyDown
- 0x3081a:$a36: get_AltKeyDown
- 0x650f0:$a36: get_AltKeyDown
- 0x2f4fa:$a37: get_Password
- 0x63dd0:$a37: get_Password
- 0x2ffb0:$a38: get_PasswordHash
- 0x64886:$a38: get_PasswordHash
- 0x30fd6:$a39: get_DefaultCredentials
|
00000004.00000000.447939474.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000004.00000000.447939474.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000004.00000000.447939474.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x3017c:$a13: get_DnsResolver
- 0x2e97e:$a20: get_LastAccessed
- 0x30b0e:$a27: set_InternalServerPort
- 0x30e2a:$a30: set_GuidMasterKey
- 0x2ea85:$a33: get_Clipboard
- 0x2ea93:$a34: get_Keyboard
- 0x2fdaf:$a35: get_ShiftKeyDown
- 0x2fdc0:$a36: get_AltKeyDown
- 0x2eaa0:$a37: get_Password
- 0x2f556:$a38: get_PasswordHash
- 0x3057c:$a39: get_DefaultCredentials
|
00000001.00000002.543889878.0000000003C98000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.543889878.0000000003C98000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000001.00000002.543889878.0000000003C98000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000001.00000002.543889878.0000000003C98000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x65866:$a13: get_DnsResolver
- 0x9a156:$a13: get_DnsResolver
- 0xcea36:$a13: get_DnsResolver
- 0x64068:$a20: get_LastAccessed
- 0x98958:$a20: get_LastAccessed
- 0xcd238:$a20: get_LastAccessed
- 0x661f8:$a27: set_InternalServerPort
- 0x9aae8:$a27: set_InternalServerPort
- 0xcf3c8:$a27: set_InternalServerPort
- 0x66514:$a30: set_GuidMasterKey
- 0x9ae04:$a30: set_GuidMasterKey
- 0xcf6e4:$a30: set_GuidMasterKey
- 0x6416f:$a33: get_Clipboard
- 0x98a5f:$a33: get_Clipboard
- 0xcd33f:$a33: get_Clipboard
- 0x6417d:$a34: get_Keyboard
- 0x98a6d:$a34: get_Keyboard
- 0xcd34d:$a34: get_Keyboard
- 0x65499:$a35: get_ShiftKeyDown
- 0x99d89:$a35: get_ShiftKeyDown
- 0xce669:$a35: get_ShiftKeyDown
|
00000001.00000002.528157488.0000000002BE2000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000000.00000002.350191112.00000000039A9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.350191112.00000000039A9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.350191112.00000000039A9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000000.00000002.350191112.00000000039A9000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x6543e:$a13: get_DnsResolver
- 0x99d2e:$a13: get_DnsResolver
- 0xce60e:$a13: get_DnsResolver
- 0x63c40:$a20: get_LastAccessed
- 0x98530:$a20: get_LastAccessed
- 0xcce10:$a20: get_LastAccessed
- 0x65dd0:$a27: set_InternalServerPort
- 0x9a6c0:$a27: set_InternalServerPort
- 0xcefa0:$a27: set_InternalServerPort
- 0x660ec:$a30: set_GuidMasterKey
- 0x9a9dc:$a30: set_GuidMasterKey
- 0xcf2bc:$a30: set_GuidMasterKey
- 0x63d47:$a33: get_Clipboard
- 0x98637:$a33: get_Clipboard
- 0xccf17:$a33: get_Clipboard
- 0x63d55:$a34: get_Keyboard
- 0x98645:$a34: get_Keyboard
- 0xccf25:$a34: get_Keyboard
- 0x65071:$a35: get_ShiftKeyDown
- 0x99961:$a35: get_ShiftKeyDown
- 0xce241:$a35: get_ShiftKeyDown
|
00000000.00000002.351247039.0000000003AB0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.351247039.0000000003AB0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.351247039.0000000003AB0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
00000000.00000002.351247039.0000000003AB0000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x307ae:$a13: get_DnsResolver
- 0x65084:$a13: get_DnsResolver
- 0x2efb0:$a20: get_LastAccessed
- 0x63886:$a20: get_LastAccessed
- 0x31140:$a27: set_InternalServerPort
- 0x65a16:$a27: set_InternalServerPort
- 0x3145c:$a30: set_GuidMasterKey
- 0x65d32:$a30: set_GuidMasterKey
- 0x2f0b7:$a33: get_Clipboard
- 0x6398d:$a33: get_Clipboard
- 0x2f0c5:$a34: get_Keyboard
- 0x6399b:$a34: get_Keyboard
- 0x303e1:$a35: get_ShiftKeyDown
- 0x64cb7:$a35: get_ShiftKeyDown
- 0x303f2:$a36: get_AltKeyDown
- 0x64cc8:$a36: get_AltKeyDown
- 0x2f0d2:$a37: get_Password
- 0x639a8:$a37: get_Password
- 0x2fb88:$a38: get_PasswordHash
- 0x6445e:$a38: get_PasswordHash
- 0x30bae:$a39: get_DefaultCredentials
|
00000004.00000002.562334194.0000000003131000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000004.00000002.562334194.0000000003131000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Process Memory Space: 321 Amita Technical 16.09.2022.exe PID: 5436 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: 321 Amita Technical 16.09.2022.exe PID: 5436 | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
Process Memory Space: 321 Amita Technical 16.09.2022.exe PID: 5436 | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x95828:$a13: get_DnsResolver
- 0xc4566:$a13: get_DnsResolver
- 0x9428a:$a20: get_LastAccessed
- 0xc2fc8:$a20: get_LastAccessed
- 0x96169:$a27: set_InternalServerPort
- 0xc4ea7:$a27: set_InternalServerPort
- 0x963c5:$a30: set_GuidMasterKey
- 0xc5103:$a30: set_GuidMasterKey
- 0x9437d:$a33: get_Clipboard
- 0xc30bb:$a33: get_Clipboard
- 0x9438b:$a34: get_Keyboard
- 0xc30c9:$a34: get_Keyboard
- 0x954fa:$a35: get_ShiftKeyDown
- 0xc4238:$a35: get_ShiftKeyDown
- 0x9550b:$a36: get_AltKeyDown
- 0xc4249:$a36: get_AltKeyDown
- 0x94398:$a37: get_Password
- 0xc30d6:$a37: get_Password
- 0x94daa:$a38: get_PasswordHash
- 0xc3ae8:$a38: get_PasswordHash
- 0x95bfc:$a39: get_DefaultCredentials
|
Process Memory Space: phine.exe PID: 5604 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: phine.exe PID: 5604 | JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | |
Process Memory Space: phine.exe PID: 5604 | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0xf90a:$a13: get_DnsResolver
- 0x2362a:$a13: get_DnsResolver
- 0x3969d:$a13: get_DnsResolver
- 0xe36c:$a20: get_LastAccessed
- 0x2208c:$a20: get_LastAccessed
- 0x380ff:$a20: get_LastAccessed
- 0x1024b:$a27: set_InternalServerPort
- 0x23f6b:$a27: set_InternalServerPort
- 0x39fde:$a27: set_InternalServerPort
- 0x104a7:$a30: set_GuidMasterKey
- 0x241c7:$a30: set_GuidMasterKey
- 0x3a23a:$a30: set_GuidMasterKey
- 0xe45f:$a33: get_Clipboard
- 0x2217f:$a33: get_Clipboard
- 0x381f2:$a33: get_Clipboard
- 0xe46d:$a34: get_Keyboard
- 0x2218d:$a34: get_Keyboard
- 0x38200:$a34: get_Keyboard
- 0xf5dc:$a35: get_ShiftKeyDown
- 0x232fc:$a35: get_ShiftKeyDown
- 0x3936f:$a35: get_ShiftKeyDown
|
Process Memory Space: InstallUtil.exe PID: 5980 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 5980 | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 5980 | Windows_Trojan_AgentTesla_d3ac2b2f | unknown | unknown | - 0x1b36f:$a13: get_DnsResolver
- 0x19dd1:$a20: get_LastAccessed
- 0x1bcb0:$a27: set_InternalServerPort
- 0x1bf0c:$a30: set_GuidMasterKey
- 0x19ec4:$a33: get_Clipboard
- 0x19ed2:$a34: get_Keyboard
- 0x1b041:$a35: get_ShiftKeyDown
- 0x1b052:$a36: get_AltKeyDown
- 0x19edf:$a37: get_Password
- 0x1a8f1:$a38: get_PasswordHash
- 0x1b743:$a39: get_DefaultCredentials
|
Click to see the 31 entries |