Walter, J. (2020, August 10). Agent Tesla | Old RAT Uses New Tricks to Stay on Top. Retrieved December 11, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAgent Tesla | Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1053.005 Scheduled Task |
MalwareAgent Tesla | Agent Tesla has achieved persistence via scheduled tasks. |
| T1055 Process Injection |
MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055.012 Process Hollowing |
MalwareAgent Tesla | Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1112 Modify Registry |
MalwareAgent Tesla | Agent Tesla can achieve persistence by modifying Registry key entries. |
| T1203 Exploitation for Client Execution |
MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
| T1218.009 Regsvcs/Regasm |
MalwareAgent Tesla | Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAgent Tesla | Agent Tesla can add itself to the Registry as a startup program to establish persistence. |
| T1552.001 Credentials In Files |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from configuration or support files. |
| T1552.002 Credentials in Registry |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from the Registry. |
| T1564.001 Hidden Files and Directories |
MalwareAgent Tesla | Agent Tesla has created hidden folders. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.