ATT&CKReferencesFortinet Agent Tesla April 2018

Fortinet Agent Tesla April 2018

Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.