VirusTotal uses CAPE sandbox to identify many malware families and determine if they can extract the malware's configuration. Since they use CAPE, we can often see their logic. Today, we'll suggest edits to a rule for AgentTesla.
Rule at end.
1/10
VirusTotal uses CAPE sandbox to identify many malware families and determine if they can extract the malware's configuration. Since they use CAPE, we can often see their logic. Today, we'll suggest edits to a rule for AgentTesla.
Rule at end.
1/10
Attached disk image file: bazaar.abuse.ch/sample/7a11d...
Extracted EXE: bazaar.abuse.ch/sample/2362b...
Attached disk image file: bazaar.abuse.ch/sample/7a11d...
Extracted EXE: bazaar.abuse.ch/sample/2362b...
File name: Factura Gastos.exe
Email accounts for data exfiltration: antonipont@grupobdb[.]com --> cludsewe3@gmail[.]com
EXE available at: bazaar.abuse.ch/sample/c7620...
File name: Factura Gastos.exe
Email accounts for data exfiltration: antonipont@grupobdb[.]com --> cludsewe3@gmail[.]com
EXE available at: bazaar.abuse.ch/sample/c7620...
www.linkedin.com/pulse/huntin...
www.linkedin.com/pulse/huntin...
#AnyRun analysis of the malware EXE at: app.any.run/tasks/8ffd01...
#AnyRun analysis of the malware EXE at: app.any.run/tasks/8ffd01...
www.netskope.com/netskope-thr...
www.netskope.com/netskope-thr...
■日時
2026/10/01(木)
■件名
Re: 請求書
■添付ファイル
請求書.rar -> 請求書.JS virustotal.com/gui/file/e9e...
tria.ge/261002-hxfpk...
情報窃取マルウェア #AgentTesla
■C2
hxxps[:]//api.telegram[.]org/
同一メールの観測報告
x.com/tdatwja/stat...
■日時
2026/10/01(木)
■件名
Re: 請求書
■添付ファイル
請求書.rar -> 請求書.JS virustotal.com/gui/file/e9e...
tria.ge/261002-hxfpk...
情報窃取マルウェア #AgentTesla
■C2
hxxps[:]//api.telegram[.]org/
同一メールの観測報告
x.com/tdatwja/stat...
hackread.com/phishing-cam...
#CyberSecurity #AgentTesla #Malware
hackread.com/phishing-cam...
#CyberSecurity #AgentTesla #Malware
Read: hackread.com/dicaprio-one...
#Cybersecurity #AgentTesla #Malware #Windows #OneBattleAfterAnother
Read: hackread.com/dicaprio-one...
#Cybersecurity #AgentTesla #Malware #Windows #OneBattleAfterAnother
And AgentTesla is one that triggers all the time.
The extracted "Configs" tell me it was from "VirusTotal_CAPE" so I check the CAPE GitHub to find the YARA rule for AgentTesla: github.com/kevoreill...
3/10
And AgentTesla is one that triggers all the time.
The extracted "Configs" tell me it was from "VirusTotal_CAPE" so I check the CAPE GitHub to find the YARA rule for AgentTesla: github.com/kevoreill...
3/10
Read: hackread.com/fakeupdates-...
#CyberSecurity #Malware #InfoStealers #InfoSec
Read: hackread.com/fakeupdates-...
#CyberSecurity #Malware #InfoStealers #InfoSec
#AgentTesla #CERTAgID #Formbook
www.matricedigitale.it/2025/10/31/c...
#AgentTesla #CERTAgID #Formbook
www.matricedigitale.it/2025/10/31/c...
Some details:
• Cruciferra has been delivered alongside zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos.
Some details:
• Cruciferra has been delivered alongside zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos.
📝 ## 🔍 Contexte
Publié sur GitHub par l'…
https://cyberveille.ch/posts/2026-07-17-darknet-mcp-server-serveur-mcp-open-source-unifiant-66-outils-de-threat-intelligence-dark-web/ #AgentTesla #Cyberveille
📝 ## 🔍 Contexte
Publié sur GitHub par l'…
https://cyberveille.ch/posts/2026-07-17-darknet-mcp-server-serveur-mcp-open-source-unifiant-66-outils-de-threat-intelligence-dark-web/ #AgentTesla #Cyberveille
Your notes hiding #malware? Cybercriminals are exploiting this popular OneNote app to deliver Redline, AgentTesla & more. Be cautious, double-check website URLs & avoid suspicious offers.
cybersecurity.att.com/blogs/labs-r...
#cybersecurity
Your notes hiding #malware? Cybercriminals are exploiting this popular OneNote app to deliver Redline, AgentTesla & more. Be cautious, double-check website URLs & avoid suspicious offers.
cybersecurity.att.com/blogs/labs-r...
#cybersecurity