Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family AgentTesla
AgentTesla is a well-known information-stealing trojan designed to steal sensitive data from infected systems. It targets credentials stored in web browsers, email clients, and other applications, often using keylogging to capture user input. The stolen information is then exfiltrated to a remote attacker.
No specific strings found for this threat
rule Trojan_MSIL_AgentTesla_NCR_2147935616_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:MSIL/AgentTesla.NCR!MTB"
threat_id = "2147935616"
type = "Trojan"
platform = "MSIL: .NET intermediate language scripts"
family = "AgentTesla"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "4"
strings_accuracy = "High"
strings:
$x_4_1 = {08 09 a3 05 00 00 1b 13 04 11 04 16 06 07 11 04 8e 69 28 1b 00 00 0a 07 11 04 8e 69 58 0b 09 17 58 0d 09 08 8e 69 32 d8} //weight: 4, accuracy: High
condition:
(filesize < 20MB) and
(all of ($x*))
}ca271b6e009c2c13b8abf07bc7ded6d11c020d328eec50fb20685ea45ba11befba3fce213c422b7888f22517be05396e8c68fd8a938ca4781c63b5e758b541f1aaed54bbc25043e6449b6cc09819acb0e6d013e5e65cf39ccaa0e12591bc5de2Isolate the affected device from the network immediately. Perform a full antivirus scan to ensure all malicious components are removed. Reset passwords for all accounts accessed from this device, as they are likely compromised.