Mr.Trunk · @mrtrunk
12 followers · 19873 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
12 followers · 19770 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
12 followers · 19671 posts · Server dromedary.seedoubleyou.me
Tarnkappe.info · @tarnkappeinfo
2135 followers · 4567 posts · Server social.tchncs.de
James_inthe_box · @james_inthe_box
273 followers · 99 posts · Server infosec.exchange

Cyberchef protip for decimal obfuscated links:

http:// OOOW3OOOOOOO233OOOOOO23OO33B2OB32O32O32B3O23BO33O3S0DFSDF0X000F0SD0000WLLL21LLLLL222LLLLL3333LELLL@3324948138/bg...................................doc

#agenttesla

Last updated 1 year ago

Today in our section on "uncoventional delivery": archives! 📦
ARJ (Archived by Robert Jung) has been around since the MS-DOS days and is occasionally used to deliver e.g. , or

You can recognize ARJ archives by their Magic: 60 EA
Extraction can be handled with 7zip for example.
For more information on the file format check out Ange Albertini's excellent graphic representation: twitter.com/angealbertini/stat

As an example we dug up a sample from last year where the delivery chain looked like this: ARJ --> RAR --> EXE
To fool the victims into opening the next file they used the common tick, e.g. .pdf.exe

IoC for those playing along at home:
162.0.223[.]13
kbfvzoboss[.]bid
alphastand[.]trade
alphastand[.]win
alphastand[.]top
➡️/alien/fre.php

PO_Payment for invoice[...].eml.arj
d0c8824d1e19ca1af0b88a477fa4cad6

SHIPPING_DL-PL-EXPRESS_EXPORT.PDF.exe
88bdf4f8fe035276da984c370e4cda2c

#malware #arj #agenttesla #formbook #GuLoader #lokibot #doubleextension #infosec #cybersecurity #blueteam

Last updated 1 year ago

CK's Technology News · @CKsTechNews
1928 followers · 4810 posts · Server cktn.todon.de
securityaffairs · @securityaffairs
454 followers · 386 posts · Server infosec.exchange
James_inthe_box · @james_inthe_box
257 followers · 73 posts · Server infosec.exchange

Hrmm...don't recall using webhooks on discord before..

app.any.run/tasks/123a8b5b-300

#agenttesla

Last updated 2 years ago


-> documents2435466.iso
->documents2435466.exe
66b45476e26891255cb747a1c470d1ac

#agenttesla

Last updated 2 years ago

James_inthe_box · @james_inthe_box
253 followers · 71 posts · Server infosec.exchange

Quick Tip 🛠️: Threat Actors like to use archiving tools for delivery to avoid and reduce file size. Today we spotted a .ace Archive containing . This technique is not new and also occasionally used for , etc.

ACE is a proprietary, legacy compression format. Unpacking these archives is dependend on the ACE version, e.g. "unace" v1.2 cannot handle ACE 2.0. We recommend github.com/droe/acefile by @droe if you ever come across such a file (screenshots see below).

FormBook

Files:
Archive e91b62f7952825d6a87775166301d018
Executable d539fcc11b4f5b96a1d89928f1ef87e7

C2:
allthekey[.]com
mgconsultantlogistics[.]com
bonaccorso[.]online
vowlashes[.]co[.]uk

#malware #detection #formbook #infostealer #agenttesla #redline #ioc

Last updated 2 years ago


43723dfa8e7a99421cb5d50cf28c86a5
-> Action Required - SIEMENS Energy -PO- 216238068.msg
-> 2023 SIEMENS Energy -PO- 216238068 DOC .zip
->2023 SIEMENS Energy -PO- 216238068 DOC.exe

#agenttesla

Last updated 2 years ago

Si soy yo · @nuria_imeq
32 followers · 38 posts · Server infosec.exchange

Campaña fichero de descarga doblemente comprimido y tamaño superior al permitido por
IOC hxxps://www/.mediafire/.com/file/166zplwbg6s85dk/Inquiry+for+Uzbekistan+Customers.tgz/file
joesandbox.com/analysis/114953

#agenttesla #rat #ransomware #sandbox

Last updated 2 years ago

Randy :donor: · @rmceoin
71 followers · 275 posts · Server infosec.exchange

@malware_traffic Thx. Working on my PE reversing skills. Apparently is .NET. dnSpy seems pretty straightforward to reverse this sample. You can see the URL that it'll reach out to and what string it uses to XOR the payload with.

#agenttesla #reverseengineering

Last updated 2 years ago

Brad · @malware_traffic
2094 followers · 84 posts · Server infosec.exchange

I forgot apparently stopped a while back, and one of the new Agent Tesla variants is called .

I wrote a Unit42 tweet about this traffic, now posted at: twitter.com/Unit42_Intel/statu

of the infection traffic, sanitized copy of the email, associated malware, and IOCs are now available at: malware-traffic-analysis.net/2

#agenttesla #originlogger #pcap

Last updated 2 years ago

Brad · @malware_traffic
2067 followers · 81 posts · Server infosec.exchange

2023-01-05 (Thursday) - malspam pushing

email --> attached .iso image --> extracted .exe --> guloader-style traffic --> Agent Tesla email data exfitration

Email available at: app.any.run/tasks/e906d78f-156

ISO available at: app.any.run/tasks/f66ff4ba-a97

Analysis of EXE available at: tria.ge/230105-28w1gsdf29

This is a -style EXE that loads an XOR-encoded binary from hxxp://savory.com[.]bd/sav/Ztvfo.png every time the infected host is logged in or rebooted.

Analysis of decoded DLL from savory.com[.]bd available at: tria.ge/230105-3xms4shc6s

#agenttesla #GuLoader

Last updated 2 years ago


HIRE PAYMENT FOR DECEMBER 2023.msg -> Swift Copy. zip -> Swift Copy.exe
5a4a1e69a0109e2cecc4327eb9ca3eef

#agenttesla

Last updated 2 years ago

Brad · @malware_traffic
1998 followers · 69 posts · Server infosec.exchange

2023-01-02 (Monday): from info I posted at twitter.com/malware_traffic/st

This is the first malware sample I've looked into for 2023!

sample at bazaar.abuse.ch/sample/c0e8dcf

Interesting (to me) data exfiltration over SMTP, similar to what I've seen before with , but this looks specific to the family.

Malware Bazaar tagged this as , but I didn't let this run long enough to get any actual keylogging. Based on what I'm seeing, it calls itself "Snake Tracker" instead of Snake Key Logger.

#snaketracker #agenttesla #snakekeylogger

Last updated 2 years ago


46412cefc3371fb14abb6f2f771dc72d

#agenttesla

Last updated 2 years ago