

Rewterz Threat Alert – FormBook Malware – Active IOCs
December 4, 2020
Rewterz Threat Alert – Ryuk Ransomware – Active IOCs
December 4, 2020
Rewterz Threat Alert – FormBook Malware – Active IOCs
December 4, 2020
Rewterz Threat Alert – Ryuk Ransomware – Active IOCs
December 4, 2020Severity
High
Analysis Summary
AgentTesla is known for stealing data from different applications on victim machines, such as browsers, FTP clients, and filedownloaders. Agent Tesla collects personal information from the victim’s machine, steals data from the victim’s clipboard,can log keystrokes, capture screenshots and access the victim’s webcam.It can kill running analysis processes and AVsoftware. The spyware also performs basic actions to check whether it is running on a virtual machine or in debug mode, inan attempt to hide its capabilities and actions from researchers. All the data it obtains is sent in encrypted form via SMTP protocol.
Impact
- Data theft
- Exposure of sensitive data/documents
Indicators of Compromise
Filename
quotation request sheet for new business query scan document 000889—-000383644377[.]exe
MD5
- 54c6ab9b65394bed4ba14597527e6b0c
- 15244163f18d97881cf794ce294b64f5
SHA-256
- a8b09f587419daeab0359367ab379bdc8eb95969da94ec1405f6722781183258
- de5dd14dca16f6fc105298e2a62f753a7e4d1723b8be9be3a8345a5f84c2ad37
- a39708c66671799439a7b6dea4997246e5c9f95ba98ee7c05e1018af0cc1b92d
- 294d3baa6d4e6b9d6e55fd9c67072d0d27f3786a4abb6b27c32fa977778fd94e
SHA1
- dd0c58a92b0ebdf516042a13340d93da19792dfd
- 50787a5f2243331d23d2655ddb5d63e60a97bdb0
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.