A short malware analysis project focused on static and dynamic analysis of an AgentTesla sample using FlareVM and industry-standard forensic tools.
This project analyzes an AgentTesla RAT sample obtained from MalwareBazaar to understand:
- Malware behavior
- Persistence mechanisms
- Evasion techniques
- Network activity
- Indicators of Compromise (IOCs)
- FlareVM
- PEview
- CFF Explorer
- FLOSS
- Resource Hacker
- Dependency Walker
- YARA
- Process Monitor
- Process Explorer
- RegShot
- Wireshark
- .NET-based malware with hidden imports
- Fake βVirtual Houseplantβ decoy GUI
- Persistence via Startup folder + PowerShell bypass
- Screenshot capture capability
- DNS connectivity checks to Microsoft domains
- Custom YARA rule successfully detected sample
- Dropped file:
llujTO.exe - Startup shortcut:
llujTO.lnk - SHA256:
301f45ab43a8e2bb80c54b6f4b5ba7b45b528b0b786a64fe40e8c3b4945baf3f
- Malware Analysis
- Threat Hunting
- YARA Rule Writing
- Windows Internals
- Dynamic Analysis
- DFIR Techniques
Aryan Hirapara M.Sc. DFIS β National Forensic Sciences University