Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.002 Wi-Fi Discovery |
MalwareAgent Tesla | Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1027 Obfuscated Files or Information |
MalwareAgent Tesla | Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings. |
| T1033 System Owner/User Discovery |
MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| T1082 System Information Discovery |
MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAgent Tesla | Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm. |
| T1497 Virtualization/Sandbox Evasion |
MalwareAgent Tesla | Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. |
| T1555 Credentials from Password Stores |
MalwareAgent Tesla | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles. |
| T1564.003 Hidden Window |
MalwareAgent Tesla | Agent Tesla has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.