๐ŸŒธ
Blog
  • ๐Ÿ“–Guide to /blog
  • ๐Ÿ‘จโ€๐Ÿ”ฌAnaysis
    • โš–๏ธHow to Scambait Like a Pro Using OSINT Tools
    • ๐ŸŽญThe Cybercrime Surge and the FBI's Battle
  • ๐ŸงชMalware Anaysis
    • โ˜ข๏ธTrojan Malware
  • ๐Ÿ™ƒRandom
    • ๐Ÿ”Meta Data Empire Expansion
Powered by GitBook
On this page
  • Malware Analysis Report: Trojan
  • Executive Summary
  • Malware Details
  • Download Site
  • File Analysis
  • Process Photo Analysis
  • String Anaysis
  • Sensitive Information Captured
  • Malware Gene
  • Conclusion
  1. Malware Anaysis

Trojan Malware

PreviousThe Cybercrime Surge and the FBI's BattleNextMeta Data Empire Expansion

Last updated 1 year ago

Malware Analysis Report: Trojan

Executive Summary

An analysis of a Trojan-malware known as Agent Tela (50% of gene) , specifically focusing on the file named "contactzx.exe" (also known as "mSSz.exe"). The malware was discovered on 07/12/2023 at 08:46:18 UTC. The report aims to outline the key characteristics of the malware, including its MD5 and SHA256 hashes, the download site, file details, and the targeted system architecture. Additionally, the report will touch upon any notable findings extracted from the provided process photo and strings.

Malware Details

  • Name: Agent Tela

  • File Name: contactzx.exe (or mSSz.exe)

  • MD5 Hash: b8c4c01af54105fef68157252a11bb69

  • SHA256 Hash: 28cf84cec3365be04caad4db5226648e4b7985928198dd05b9a11d6a0f1975ca

Download Site

The malware was found to be downloaded from the following site:

  • Download Site:

File Analysis

  • File Name: contactzx.exe

  • File Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

  • File Size: 575.00 KB (588800 bytes)

  • Discovery Date: 07/12/2023

  • Targeted System: Intel 386 or later processors and compatible processors

Process Photo Analysis

String Anaysis

Sensitive Information Captured

The Trojan has the following capabilities to capture sensitive information:

Malware Gene

Conclusion

The Agent Tela Trojan malware, in the form of the contactzx.exe file, was discovered on 07/12/2023. It is a PE32 executable specifically designed for Intel 386 or later processors. The Trojan's primary purpose and behavior cannot be determined without additional information, such as the process photo and detailed string analysis.

โ€”

Sources and Scans to read

Input Capture: Keylogging

Clipboard Data

Screen Capture

T1056.001
T1115
T1113
https://analyze.intezer.com/analyses/80be3465-2edb-4fc9-bc33-c8fdb41454b6/sub/e37d88fe-1804-4282-9347-0b585812bd77/related-samples
https://www.virustotal.com/gui/file/28cf84cec3365be04caad4db5226648e4b7985928198dd05b9a11d6a0f1975ca
๐Ÿงช
โ˜ข๏ธ
Page cover image
http://87.121.221.212/contactzx[.]exe
The process photo above shows the dynamic analysis of the malware when it is run.
The strings analysis above shows a list of what the Trojan is trying to take in and all the processes.