ATT&CKReferencesDigiTrust Agent Tesla Jan 2017

DigiTrust Agent Tesla Jan 2017

The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1071.001
Web Protocols
MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

T1087.001
Local Account
MalwareAgent Tesla

Agent Tesla can collect account information from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1124
System Time Discovery
MalwareAgent Tesla

Agent Tesla can collect the timestamp from the victim’s machine.

T1125
Video Capture
MalwareAgent Tesla

Agent Tesla can access the victim’s webcam and record video.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.