Agent Tesla Keylogger delivered using cybersquatting
ID: 0f731f0c-de20-5156-96a3-9e302e095589
STIX ID: report--0f731f0c-de20-5156-96a3-9e302e095589
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ analyzed an AgentTesla keylogger campaign that used cybersquatting (diodetechs.com) and malicious Office macros to deliver a Windows .NET keylogger (cc.exe, MD5 e4117e6974363cac8b37e5e3ff5d07a6). The report documents infection and persistence mechanisms, modules for keylogging, screenshots, password theft and anti-analysis, C2 communication and data exfiltration formats, and provides IOCs; the malicious domain was suspended after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
