Skip to content

Repository files navigation

AgentTesla RAT Malware Analysis

A short malware analysis project focused on static and dynamic analysis of an AgentTesla sample using FlareVM and industry-standard forensic tools.

πŸ” Overview

This project analyzes an AgentTesla RAT sample obtained from MalwareBazaar to understand:

  • Malware behavior
  • Persistence mechanisms
  • Evasion techniques
  • Network activity
  • Indicators of Compromise (IOCs)

πŸ›  Tools Used

  • FlareVM
  • PEview
  • CFF Explorer
  • FLOSS
  • Resource Hacker
  • Dependency Walker
  • YARA
  • Process Monitor
  • Process Explorer
  • RegShot
  • Wireshark

πŸ“Œ Key Findings

  • .NET-based malware with hidden imports
  • Fake β€œVirtual Houseplant” decoy GUI
  • Persistence via Startup folder + PowerShell bypass
  • Screenshot capture capability
  • DNS connectivity checks to Microsoft domains
  • Custom YARA rule successfully detected sample

🚨 IOCs

  • Dropped file: llujTO.exe
  • Startup shortcut: llujTO.lnk
  • SHA256: 301f45ab43a8e2bb80c54b6f4b5ba7b45b528b0b786a64fe40e8c3b4945baf3f

πŸ“š Skills Demonstrated

  • Malware Analysis
  • Threat Hunting
  • YARA Rule Writing
  • Windows Internals
  • Dynamic Analysis
  • DFIR Techniques

πŸ‘¨β€πŸ’» Author

Aryan Hirapara M.Sc. DFIS β€” National Forensic Sciences University

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages