{"id":3143,"date":"2021-06-19T21:55:34","date_gmt":"2021-06-20T02:55:34","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3143"},"modified":"2021-06-19T21:55:41","modified_gmt":"2021-06-20T02:55:41","slug":"agent-tesla-an-evolving-old-enemy","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/","title":{"rendered":"Agent Tesla is an evolving old enemy"},"content":{"rendered":"\n<p>As with Netwire, Agent Tesla is an old acquaintance that has been evolving in recent years. These two threats are classified as remote control tools (RAT) and are used by both criminals and operators associated with one of the numerous groups of advanced persistent threats (APTs). This malware is developed with the .NET framework and is used to spy on and steal information from compromised computers, since it has the ability to extract credentials from different software, obtain cookies from Internet browsers, record the keystrokes of the machine (Keylogging), as well as taking screenshots and the clipboard (clipboard).<\/p>\n\n\n\n<p>This malicious code uses different methods to send the collected information to the attacker. In turn, it has been seen that this threat can be included within a packer with different layers of obfuscation. This is used to try to evade security solutions and hinder the malware investigation and analysis process. These packers can implement different techniques to obtain information from the machine on which it is running, to, for example, find out if it is a virtual machine or a sandbox machine, and if so, prevent its execution.<\/p>\n\n\n\n<p>One of the peculiarities of Agent Tesla is that it has been offered for a long time as if it were just another commercial software, even offering subscription services and even having a web page from which to contract it and see its characteristics. This malware has also been involved even in targeted campaigns.<\/p>\n\n\n\n<p>This threat is usually spread through phishing emails that include a malicious attachment with which they seek to trick the user who receives the email into downloading and executing this content. For example, Agent Tesla has been seen to be distributed through emails that impersonated well-known logistics service companies, and which included an attachment that appeared to be related to the shipment of a package, but was actually malicious content.<\/p>\n\n\n\n<p>Agent Tesla has different features and functionalities that allow it to perform the malicious actions mentioned above. On the one hand, it has two classes (class) that contain variables and methods related to the configuration. Malware may vary a little in its behavior from these configuration classes, but it is mainly capable of carrying out the following actions:<\/p>\n\n\n\n<p><strong><em>\u25b8Persistence in the victim&#8217;s machine<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong><em><strong>Uninstalling the threat<\/strong><\/em><\/p>\n\n\n\n<p><strong><em>\u25b8Determine the method of exfiltration of the collected information<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Obtain the public IP of the victim&#8217;s machine<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Obtain information about the victim machine (operating system, CPU, RAM, username, etc.)<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong><em><strong>Take screenshots of the victim&#8217;s machine <\/strong><\/em><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong><em><strong>Run a keylogger<\/strong><\/em><\/p>\n\n\n\n<p>This is why security companies are always and we are so demanding about not trusting everything you see on the Internet such as: Emails, announcements, news, Links, etc. Because these can be intended for malicious purposes.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/\">Phorpiex, an ancient threat that resurfaces again<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/necro-python-bot-with-problematic-features\/\">Necro Python Bot with Problematic Features<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As with Netwire, Agent Tesla is an old acquaintance that has been evolving in recent years. These two threats are classified as remote control tools (RAT) and are used by both criminals and operators associated with one of the numerous groups of advanced persistent threats (APTs). This malware is developed with the .NET framework and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3144,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Agent Tesla is an evolving old enemy - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Agent Tesla is an evolving old enemy - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-20T02:55:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-20T02:55:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"506\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Agent Tesla is an evolving old enemy\",\"datePublished\":\"2021-06-20T02:55:34+00:00\",\"dateModified\":\"2021-06-20T02:55:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/\"},\"wordCount\":476,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/imagen-1.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/\",\"name\":\"Agent Tesla is an evolving old enemy - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/imagen-1.jpg\",\"datePublished\":\"2021-06-20T02:55:34+00:00\",\"dateModified\":\"2021-06-20T02:55:41+00:00\",\"description\":\"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/imagen-1.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/imagen-1.jpg\",\"width\":900,\"height\":506},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/agent-tesla-an-evolving-old-enemy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Agent Tesla is an evolving old enemy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Agent Tesla is an evolving old enemy - Truxgo Server Blog","description":"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/","og_locale":"es_MX","og_type":"article","og_title":"Agent Tesla is an evolving old enemy - Truxgo Server Blog","og_description":"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......","og_url":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-20T02:55:34+00:00","article_modified_time":"2021-06-20T02:55:41+00:00","og_image":[{"width":900,"height":506,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"3 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Agent Tesla is an evolving old enemy","datePublished":"2021-06-20T02:55:34+00:00","dateModified":"2021-06-20T02:55:41+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/"},"wordCount":476,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/","url":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/","name":"Agent Tesla is an evolving old enemy - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg","datePublished":"2021-06-20T02:55:34+00:00","dateModified":"2021-06-20T02:55:41+00:00","description":"Threats have existed for a long time on the Web, this is the case of an old enemy that we will see today called Agent Tesla......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/imagen-1.jpg","width":900,"height":506},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/agent-tesla-an-evolving-old-enemy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Agent Tesla is an evolving old enemy"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3143"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3143\/revisions"}],"predecessor-version":[{"id":3154,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3143\/revisions\/3154"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3144"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}