ATT&CKReferencesSentinelLabs Agent Tesla Aug 2020

SentinelLabs Agent Tesla Aug 2020

Walter, J. (2020, August 10). Agent Tesla | Old RAT Uses New Tricks to Stay on Top. Retrieved December 11, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1053.005
Scheduled Task
MalwareAgent Tesla

Agent Tesla has achieved persistence via scheduled tasks.

T1055
Process Injection
MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055.012
Process Hollowing
MalwareAgent Tesla

Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1112
Modify Registry
MalwareAgent Tesla

Agent Tesla can achieve persistence by modifying Registry key entries.

T1203
Exploitation for Client Execution
MalwareAgent Tesla

Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.

T1218.009
Regsvcs/Regasm
MalwareAgent Tesla

Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity.

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

T1552.001
Credentials In Files
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from configuration or support files.

T1552.002
Credentials in Registry
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from the Registry.

T1564.001
Hidden Files and Directories
MalwareAgent Tesla

Agent Tesla has created hidden folders.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.