ATT&CKReferencesFortinet Agent Tesla June 2017

Fortinet Agent Tesla June 2017

Zhang, X. (2017, June 28). In-Depth Analysis of A New Variant of .NET Malware AgentTesla. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1057
Process Discovery
MalwareAgent Tesla

Agent Tesla can list the current running processes on the system.

T1071.001
Web Protocols
MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1685
Disable or Modify Tools
MalwareAgent Tesla

Agent Tesla has the capability to kill any running analysis processes and AV software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.