The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAgent Tesla | Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings. |
| T1033 System Owner/User Discovery |
MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| T1087.001 Local Account |
MalwareAgent Tesla | Agent Tesla can collect account information from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareAgent Tesla | Agent Tesla can download additional files for execution on the victim’s machine. |
| T1113 Screen Capture |
MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| T1124 System Time Discovery |
MalwareAgent Tesla | Agent Tesla can collect the timestamp from the victim’s machine. |
| T1125 Video Capture |
MalwareAgent Tesla | Agent Tesla can access the victim’s webcam and record video. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.