Zhang, X. (2017, June 28). In-Depth Analysis of A New Variant of .NET Malware AgentTesla. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1057 Process Discovery |
MalwareAgent Tesla | Agent Tesla can list the current running processes on the system. |
| T1071.001 Web Protocols |
MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| T1071.003 Mail Protocols |
MalwareAgent Tesla | Agent Tesla has used SMTP for C2 communications. |
| T1082 System Information Discovery |
MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1113 Screen Capture |
MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| T1115 Clipboard Data |
MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| T1685 Disable or Modify Tools |
MalwareAgent Tesla | Agent Tesla has the capability to kill any running analysis processes and AV software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.