6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fbAgentTesla: 6bd72078 — Naked .NET PE32, Python-masquerade version info, builder-default unobfuscated metadata
Executive Summary
A commodity AgentTesla infostealer compiled as a direct .NET Framework PE32 executable — no AutoItSC wrapper, no PyInstaller dropper, no Delphi stub. Builder-default method names are left unobfuscated in CLR metadata (EnableKeylogger, EnableClipboardLogger, VaultEnumerateVaults, FtpHost, PublicIpAddressGrab), making family attribution trivial. Version info masquerades as a Python 3.11.3 installer (Python Software Foundation, setup). Static-only analysis (CAPE skipped — no Windows guest); no hardcoded C2 credentials recovered, but FTP/HTTP/WebClient exfil channels and Tor panel option are present in the metadata surface.
What It Is
| Field | Value | Source |
|---|---|---|
| SHA-256 | 6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb |
^[triage.json:3] |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | ^[file.txt:1] |
| Size | 245,760 bytes (240 KB) | ^[triage.json:13] |
| Compilation timestamp | Thu Jan 18 19:15:54 2024 UTC | ^[pefile.txt:34] |
| Linker | MSVC 11.0 (MajorLinkerVersion 0xB) | ^[pefile.txt:45-46] |
| .NET runtime | CIL — mscorlib references, v4.0.30319 |
^[strings.txt:8,402] |
| Packing | None detected | ^[binwalk.txt], ^[pefile.txt] |
| Signed | No | ^[rabin2-info.txt:27] |
| Version-info masquerade | Python 3.11.3 (64-bit), Python Software Foundation, internal name f45b853c-c9d3-495e-9acb-d41a4a90029f.exe |
^[pefile.txt:233-243], ^[exiftool.json:36-43] |
| Entropy | .text 5.01, .rsrc 3.86, .reloc 0.10 | ^[pefile.txt:92,112,132] |
How It Works
This sample is a naked .NET assembly — the AgentTesla payload executes directly without a wrapper dropper. This is unusual in this corpus, where prior AgentTesla samples (127c404a, 0efed3b3, 6718622d, b017d189, accd2ccd) were all delivered via AutoItSC loaders, and 0ce2a9be via a Delphi VCL stub. The builder operator chose to export the raw .NET PE, possibly for direct attachment delivery or testing.
The binary carries a full surveillance and credential-theft toolkit inferred from unobfuscated CLR metadata and capa static analysis:
- Keylogging via
SetWindowsHookExwithWH_KEYBOARD_LLglobal hook ^[strings.txt:241-243,678-684,1364-1367], ^[capa.txt:97-98] - Clipboard monitoring via
SetClipboardViewerandChangeClipboardChain^[strings.txt:506,950-953,1112-1113], ^[capa.txt:15], ^[capa.txt:129] - Screenshot capture via
CopyFromScreen/GetPrimaryScreen^[strings.txt:946-948], ^[capa.txt:18], ^[capa.txt:101] - Browser credential theft targeting Mozilla and Chromium families (
MozillaBrowserList,ChromiumBrowserList) ^[strings.txt:1306-1307] - Windows Credential Manager / Vault API theft (
VaultEnumerateVaults,VaultGetItem,VaultOpenVault) ^[strings.txt:1129,1184-1185,1262], ^[capa.txt:104-105] - DPAPI decryption of protected credential blobs ^[strings.txt:388-391], ^[capa.txt:118]
- Anti-analysis via
CheckRemoteDebuggerPresent, anti-VM strings, and WMI system queries ^[strings.txt:1285-1287], ^[capa.txt:88-94], ^[capa.txt:129] - System fingerprinting (OS version, disk info, process enumeration, registry queries, environment variables) ^[capa.txt:26-32], ^[capa.txt:154-155]
- Process creation with modified I/O handles ^[capa.txt:156-158]
Exfiltration channels (present but no hardcoded credentials recovered):
- FTP —
FtpWebRequest,FtpHost,FtpUser,FtpPassword^[strings.txt:1103,509-511,1309-1310], ^[capa.txt:106] - HTTP/WebClient —
HttpWebRequest,WebClient,PublicUserAgent,DownloadString^[strings.txt:1301-1303,1272-1273,785], ^[capa.txt:107-111] - Tor —
EnableTorPanelboolean flag present ^[strings.txt:897] - Public IP resolution —
PublicIpAddressGrab^[strings.txt:400]
Persistence indicators (static):
- Registry Run references:
StartupRegName^[strings.txt:611] - Startup directory staging:
StartupDirectoryName,AppAddStartup,HideFileStartup^[strings.txt:631-632,1052-1055]
Notable absent features (compared to siblings):
- No hardcoded SMTP server, username, or password (unlike
0efed3b3withmail.rrcindia.co.in) - No hardcoded email client targets (Outlook, Thunderbird, etc.) — strings absent
- No VNC/VPN client strings — unlike
0efed3b3 - No Discord/Telegram exfil strings — unlike some variants
- No hardcoded IP or domain C2 strings — config likely runtime-decrypted or builder-configured
Decompiled Behavior
Ghidra/radare2 analysis of the CIL bytecode confirms the entry point at 0x00402e34 (entry0) delegates to the CLR runtime via _CorExeMain in mscoree.dll. The binary exposes 1050+ methods with builder-default unobfuscated names. Key method families observed:
method.*.EnableKeylogger*/method.*.EnableClipboardLogger*/method.*.EnableScreenLogger*— toggles surveillance modulesmethod.*.VaultEnumerateVaults*/method.*.VaultGetItem*— Windows Vault API credential enumerationmethod.*.FtpHost*/method.*.FtpUser*/method.*.FtpPassword*— FTP C2 config getters/settersmethod.*.PublicIpAddress*/method.*.PublicUserAgent*— HTTP beaconing configmethod.*.CheckRemoteDebuggerPresent*— anti-debug gate
The code makes heavy use of .NET crypto primitives:
RijndaelManaged/AesManagedfor payload/config decryption ^[strings.txt:432,893], ^[capa.txt:117-118]BCryptOpenAlgorithmProvider/BCryptDecryptvia P/Invoke tobcrypt.dll^[strings.txt:259,256,898-906,1296-1297], ^[capa.txt:115]MD5CryptoServiceProvider/SHA1CryptoServiceProviderfor hashing ^[strings.txt:1076-1077], ^[capa.txt:119-120]ProtectedData.Unprotectfor DPAPI credential decryption ^[strings.txt:388-391], ^[capa.txt:118]- Base64 encoding/decoding (15+ matches) ^[capa.txt:112-114]
C2 Infrastructure
No hardcoded C2 IOCs were recovered statically. The following channels are present in the binary surface but their endpoints are likely runtime-decrypted or configured by the builder:
- FTP (
FtpWebRequest) — server, user, and password via builder-configured properties - HTTP/WebClient — User-Agent masquerade (
PublicUserAgent), URL viaDownloadString - Tor — optional
EnableTorPanelflag suggests onion-routed C2 fallback - Public IP check —
PublicIpAddressGrabimplies a geolocation or hosting-detection query
No mutex names, named pipes, or registry keys beyond persistence indicators were recovered.
Interesting Tidbits
- Builder opsec: zero. Method names like
EnableKeylogger,EnableClipboardLogger,VaultGetItem, andFtpPasswordare stock AgentTesla builder defaults. No ConfuserEx, no SmartAssembly, no string encryption. This is either a test build or a lowest-tier MaaS customer. - Version-info masquerade: Claims to be
Python 3.11.3 (64-bit)byPython Software Foundation, file descriptionsetup, internal name a GUID (f45b853c-c9d3-495e-9acb-d41a4a90029f.exe). The GUID also appears in the PE metadata as the internal filename — likely a builder-generated project ID. - Second GUID:
$ac817265-7162-4840-9799-486144a753d9appears in#Stringsmetadata — possibly a second builder project ID or a module GUID. - No wrapper, no loader: Unlike every other AgentTesla in this corpus, this sample is a direct .NET PE. This could indicate the builder was run in "direct output" mode (export compiled assembly) rather than "bundle with dropper" mode.
- Floss failed: The
floss.txtartifact shows a CLI argument parsing error, not decoded strings. The .NET metadata strings are already plaintext — floss had nothing to decode. - Capa false positives: Standard .NET
DebuggerNonUserCodeAttributeetc. may trigger anti-debug signatures. Cross-reference with string evidence before trusting capa's anti-debug claims in isolation.
How To Mess With It (Homelab Replication)
Goal: Build a .NET Framework PE32 with comparable capa fingerprint for testing EDR/hunt rules.
Toolchain:
- Visual Studio 2022 or
dotnet buildtargeting .NET Framework 4.0+ - C# console or WinForms project
Recipe:
- Create a C# project with references to
System.Security,System.Drawing,System.Management,System.Net,System.Windows.Forms. - Add P/Invoke imports for
SetWindowsHookEx,CheckRemoteDebuggerPresent,VaultEnumerateVaults,BCryptOpenAlgorithmProvider,NtQuerySystemInformation. - Implement classes named
EnableKeylogger,EnableClipboardLogger,EnableScreenLogger,VaultEnumerateVaults,FtpHost,PublicIpAddressGrab. - Use
HttpWebRequest,FtpWebRequest,WebClientfor network ops. - Add
RijndaelManagedorAesManagedcrypto usage. - Compile as PE32 (x86), GUI subsystem.
- Edit VS_VERSIONINFO resource to masquerade as
Python 3.11.3 (64-bit).
Verification:
capa reproducer.exe
Expect hits for: keylogging, clipboard, screenshot, HTTP client, FTP send, Base64 encode/decode, AES encrypt/decrypt, DPAPI, registry query, process enumeration, WMI access, anti-debugger check, anti-VM strings.
Deployable Signatures
YARA Rule
rule AgentTesla_NakedDotNet_2024 {
meta:
description = "Naked .NET AgentTesla with builder-default unobfuscated method names"
author = "PacketPursuit"
date = "2026-07-30"
hash = "6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb"
confidence = "high"
strings:
$s1 = "EnableKeylogger" wide ascii
$s2 = "EnableClipboardLogger" wide ascii
$s3 = "EnableScreenLogger" wide ascii
$s4 = "VaultEnumerateVaults" wide ascii
$s5 = "VaultGetItem" wide ascii
$s6 = "VaultOpenVault" wide ascii
$s7 = "FtpHost" wide ascii
$s8 = "FtpPassword" wide ascii
$s9 = "PublicIpAddressGrab" wide ascii
$s10 = "MozillaBrowserList" wide ascii
$s11 = "ChromiumBrowserList" wide ascii
$s12 = "StartupRegName" wide ascii
$s13 = "AppAddStartup" wide ascii
$s14 = "HideFileStartup" wide ascii
$s15 = "EnableTorPanel" wide ascii
$s16 = "CheckRemoteDebuggerPresent" wide ascii
$dot1 = "System.Security.Cryptography" wide ascii
$dot2 = "System.Drawing" wide ascii
$dot3 = "System.Management" wide ascii
$dot4 = "System.Windows.Forms" wide ascii
$dot5 = "System.Net" wide ascii
$bcrypt = "BCryptOpenAlgorithmProvider" wide ascii
$dpapi = "ProtectedData" wide ascii
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI
and pe.imports("mscoree.dll", "_CorExeMain")
and 6 of ($s*)
and 3 of ($dot*)
and any of ($bcrypt, $dpapi)
}
Sigma Rule
title: AgentTesla .NET Infostealer Execution Detection
status: experimental
description: Detects execution of AgentTesla .NET infostealer with builder-default method names and surveillance toolkit
logsource:
category: process_creation
product: windows
detection:
selection:
- CommandLine|contains:
- 'EnableKeylogger'
- 'EnableClipboardLogger'
- 'EnableScreenLogger'
- 'VaultEnumerateVaults'
- 'VaultGetItem'
- 'VaultOpenVault'
- 'PublicIpAddressGrab'
- 'MozillaBrowserList'
- 'ChromiumBrowserList'
- ImageLoaded:
- '*\vaultcli.dll'
- CommandLine|contains:
- 'SetWindowsHookEx'
- 'WH_KEYBOARD_LL'
filter:
Image|endswith:
- 'devenv.exe'
- 'msbuild.exe'
condition: selection and not filter
falsepositives:
- Legitimate security research tools using identical method names
- Penetration testing frameworks
level: high
IOC List
| Indicator | Type | Notes |
|---|---|---|
6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb |
SHA-256 | This sample |
00c4222201ab023c32637707d091e643 |
MD5 | |
f45b853c-c9d3-495e-9acb-d41a4a90029f |
GUID | Internal filename / builder project ID |
$ac817265-7162-4840-9799-486144a753d9 |
GUID | Secondary metadata GUID |
EnableKeylogger |
String | Builder-default method name |
EnableClipboardLogger |
String | Builder-default method name |
VaultEnumerateVaults |
String | Windows Vault API call |
PublicIpAddressGrab |
String | IP resolution routine |
StartupRegName |
String | Registry persistence indicator |
EnableTorPanel |
String | Optional Tor C2 flag |
MozillaBrowserList / ChromiumBrowserList |
String | Browser targeting |
Behavioral Fingerprint Statement
This binary is a .NET Framework PE32 compiled with MSVC 11.0, GUI subsystem, three sections, and imports only mscoree._CorExeMain. It carries unobfuscated CLR metadata with method names matching AgentTesla builder defaults (EnableKeylogger, EnableClipboardLogger, VaultEnumerateVaults, FtpHost, PublicIpAddressGrab). At runtime it installs a global low-level keyboard hook (SetWindowsHookEx + WH_KEYBOARD_LL), monitors clipboard changes (SetClipboardViewer), captures screenshots (CopyFromScreen), enumerates Windows Vault credentials (vaultcli.dll), queries WMI for system information, and exfiltrates via FTP (FtpWebRequest) and HTTP (WebClient/HttpWebRequest). It checks for debuggers (CheckRemoteDebuggerPresent) and references anti-VM strings. Persistence is attempted via registry Run keys and startup directory placement. No packing or obfuscation is applied.
Detection Signatures
capa → MITRE ATT&CK mapping:
| capa Capability | ATT&CK Technique |
|---|---|
| log keystrokes via application hook | T1056.001 |
| log keystrokes via polling | T1056.001 |
| capture screenshot | T1113 |
| read clipboard data | T1115 |
| create HTTP request / send request in .NET | T1071.001 |
| send file using FTP | T1041 |
| check for debugger via API | T1622 |
| reference anti-VM strings | T1497.001 |
| query environment variable | T1082 |
| query or enumerate registry key/value | T1012 |
| enumerate processes | T1057 |
| access WMI data in .NET | T1047 |
| decode data using Base64 in .NET | T1140 |
| encrypt/decrypt data via BCrypt / AES via .NET | T1573 |
| bypass Mark of the Web | T1553.005 |
| set global application hook | T1056.001 |
| get graphical window text | T1010 |
| get keyboard layout | T1082 |
| get system information on Windows | T1082 |
| get OS version in .NET | T1082 |
| create process in .NET | T1059.003 |
| terminate process | T1489 |
| suspend thread | T1055 |
References
- Artifact ID:
ee3afa89-9fba-40b1-b5fc-83b1044eb264 - OpenCTI labels:
agenttesla,exe,malware-bazaar - Filename at triage:
origin.exe - Related wiki pages: agenttesla, browser-credential-harvesting, smtp-exfiltration, clipboard-hijack-cryptocurrency, version-info-masquerade
Provenance
- Static analysis performed on 2026-07-30 using file, exiftool, pefile, strings, capa v7, binwalk, radare2 (CIL analysis), and manual grep inspection.
- CAPE sandbox detonation skipped — no Windows guest available.
- floss tool failed with argument-parsing error; .NET metadata strings are already plaintext.
^[sample 6bd72078/file.txt] ^[sample 6bd72078/pefile.txt] ^[sample 6bd72078/strings.txt] ^[sample 6bd72078/capa.txt] ^[sample 6bd72078/binwalk.txt] ^[sample 6bd72078/rabin2-info.txt] ^[sample 6bd72078/exiftool.json] ^[sample 6bd72078/triage.json]