Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
December 4, 2020
Rewterz
Rewterz Threat Alert – Ryuk Ransomware – Active IOCs
December 4, 2020

Rewterz Threat Alert – Agent Tesla Malware – Active IOCs

Severity

High

Analysis Summary

AgentTesla is known for stealing data from different applications on victim machines, such as browsers, FTP clients, and filedownloaders. Agent Tesla collects personal information from the victim’s machine, steals data from the victim’s clipboard,can log keystrokes, capture screenshots and access the victim’s webcam.It can kill running analysis processes and AVsoftware. The spyware also performs basic actions to check whether it is running on a virtual machine or in debug mode, inan attempt to hide its capabilities and actions from researchers. All the data it obtains is sent in encrypted form via SMTP protocol.

Impact

  • Data theft 
  • Exposure of sensitive data/documents

Indicators of Compromise

Filename

quotation request sheet for new business query scan document 000889—-000383644377[.]exe

MD5

  • 54c6ab9b65394bed4ba14597527e6b0c
  • 15244163f18d97881cf794ce294b64f5

SHA-256

  • a8b09f587419daeab0359367ab379bdc8eb95969da94ec1405f6722781183258
  • de5dd14dca16f6fc105298e2a62f753a7e4d1723b8be9be3a8345a5f84c2ad37
  • a39708c66671799439a7b6dea4997246e5c9f95ba98ee7c05e1018af0cc1b92d
  • 294d3baa6d4e6b9d6e55fd9c67072d0d27f3786a4abb6b27c32fa977778fd94e

SHA1

  • dd0c58a92b0ebdf516042a13340d93da19792dfd
  • 50787a5f2243331d23d2655ddb5d63e60a97bdb0

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.