typeanalysisfamilyagentteslaconfidencehighcreated2026-07-30updated2026-07-30malware-familyinfostealerdotnetkeyloggerclipboard-hijackscreenshot-capturebrowser-credential-theftsmtp-exfiltrationftp-exfiltrationanti-vmversion-info-masquerade
SHA-256: 6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb

AgentTesla: 6bd72078 — Naked .NET PE32, Python-masquerade version info, builder-default unobfuscated metadata

Executive Summary

A commodity AgentTesla infostealer compiled as a direct .NET Framework PE32 executable — no AutoItSC wrapper, no PyInstaller dropper, no Delphi stub. Builder-default method names are left unobfuscated in CLR metadata (EnableKeylogger, EnableClipboardLogger, VaultEnumerateVaults, FtpHost, PublicIpAddressGrab), making family attribution trivial. Version info masquerades as a Python 3.11.3 installer (Python Software Foundation, setup). Static-only analysis (CAPE skipped — no Windows guest); no hardcoded C2 credentials recovered, but FTP/HTTP/WebClient exfil channels and Tor panel option are present in the metadata surface.

What It Is

Field Value Source
SHA-256 6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb ^[triage.json:3]
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt:1]
Size 245,760 bytes (240 KB) ^[triage.json:13]
Compilation timestamp Thu Jan 18 19:15:54 2024 UTC ^[pefile.txt:34]
Linker MSVC 11.0 (MajorLinkerVersion 0xB) ^[pefile.txt:45-46]
.NET runtime CIL — mscorlib references, v4.0.30319 ^[strings.txt:8,402]
Packing None detected ^[binwalk.txt], ^[pefile.txt]
Signed No ^[rabin2-info.txt:27]
Version-info masquerade Python 3.11.3 (64-bit), Python Software Foundation, internal name f45b853c-c9d3-495e-9acb-d41a4a90029f.exe ^[pefile.txt:233-243], ^[exiftool.json:36-43]
Entropy .text 5.01, .rsrc 3.86, .reloc 0.10 ^[pefile.txt:92,112,132]

How It Works

This sample is a naked .NET assembly — the AgentTesla payload executes directly without a wrapper dropper. This is unusual in this corpus, where prior AgentTesla samples (127c404a, 0efed3b3, 6718622d, b017d189, accd2ccd) were all delivered via AutoItSC loaders, and 0ce2a9be via a Delphi VCL stub. The builder operator chose to export the raw .NET PE, possibly for direct attachment delivery or testing.

The binary carries a full surveillance and credential-theft toolkit inferred from unobfuscated CLR metadata and capa static analysis:

  • Keylogging via SetWindowsHookEx with WH_KEYBOARD_LL global hook ^[strings.txt:241-243,678-684,1364-1367], ^[capa.txt:97-98]
  • Clipboard monitoring via SetClipboardViewer and ChangeClipboardChain ^[strings.txt:506,950-953,1112-1113], ^[capa.txt:15], ^[capa.txt:129]
  • Screenshot capture via CopyFromScreen / GetPrimaryScreen ^[strings.txt:946-948], ^[capa.txt:18], ^[capa.txt:101]
  • Browser credential theft targeting Mozilla and Chromium families (MozillaBrowserList, ChromiumBrowserList) ^[strings.txt:1306-1307]
  • Windows Credential Manager / Vault API theft (VaultEnumerateVaults, VaultGetItem, VaultOpenVault) ^[strings.txt:1129,1184-1185,1262], ^[capa.txt:104-105]
  • DPAPI decryption of protected credential blobs ^[strings.txt:388-391], ^[capa.txt:118]
  • Anti-analysis via CheckRemoteDebuggerPresent, anti-VM strings, and WMI system queries ^[strings.txt:1285-1287], ^[capa.txt:88-94], ^[capa.txt:129]
  • System fingerprinting (OS version, disk info, process enumeration, registry queries, environment variables) ^[capa.txt:26-32], ^[capa.txt:154-155]
  • Process creation with modified I/O handles ^[capa.txt:156-158]

Exfiltration channels (present but no hardcoded credentials recovered):

  • FTP — FtpWebRequest, FtpHost, FtpUser, FtpPassword ^[strings.txt:1103,509-511,1309-1310], ^[capa.txt:106]
  • HTTP/WebClient — HttpWebRequest, WebClient, PublicUserAgent, DownloadString ^[strings.txt:1301-1303,1272-1273,785], ^[capa.txt:107-111]
  • Tor — EnableTorPanel boolean flag present ^[strings.txt:897]
  • Public IP resolution — PublicIpAddressGrab ^[strings.txt:400]

Persistence indicators (static):

  • Registry Run references: StartupRegName ^[strings.txt:611]
  • Startup directory staging: StartupDirectoryName, AppAddStartup, HideFileStartup ^[strings.txt:631-632,1052-1055]

Notable absent features (compared to siblings):

  • No hardcoded SMTP server, username, or password (unlike 0efed3b3 with mail.rrcindia.co.in)
  • No hardcoded email client targets (Outlook, Thunderbird, etc.) — strings absent
  • No VNC/VPN client strings — unlike 0efed3b3
  • No Discord/Telegram exfil strings — unlike some variants
  • No hardcoded IP or domain C2 strings — config likely runtime-decrypted or builder-configured

Decompiled Behavior

Ghidra/radare2 analysis of the CIL bytecode confirms the entry point at 0x00402e34 (entry0) delegates to the CLR runtime via _CorExeMain in mscoree.dll. The binary exposes 1050+ methods with builder-default unobfuscated names. Key method families observed:

  • method.*.EnableKeylogger* / method.*.EnableClipboardLogger* / method.*.EnableScreenLogger* — toggles surveillance modules
  • method.*.VaultEnumerateVaults* / method.*.VaultGetItem* — Windows Vault API credential enumeration
  • method.*.FtpHost* / method.*.FtpUser* / method.*.FtpPassword* — FTP C2 config getters/setters
  • method.*.PublicIpAddress* / method.*.PublicUserAgent* — HTTP beaconing config
  • method.*.CheckRemoteDebuggerPresent* — anti-debug gate

The code makes heavy use of .NET crypto primitives:

  • RijndaelManaged / AesManaged for payload/config decryption ^[strings.txt:432,893], ^[capa.txt:117-118]
  • BCryptOpenAlgorithmProvider / BCryptDecrypt via P/Invoke to bcrypt.dll ^[strings.txt:259,256,898-906,1296-1297], ^[capa.txt:115]
  • MD5CryptoServiceProvider / SHA1CryptoServiceProvider for hashing ^[strings.txt:1076-1077], ^[capa.txt:119-120]
  • ProtectedData.Unprotect for DPAPI credential decryption ^[strings.txt:388-391], ^[capa.txt:118]
  • Base64 encoding/decoding (15+ matches) ^[capa.txt:112-114]

C2 Infrastructure

No hardcoded C2 IOCs were recovered statically. The following channels are present in the binary surface but their endpoints are likely runtime-decrypted or configured by the builder:

  • FTP (FtpWebRequest) — server, user, and password via builder-configured properties
  • HTTP/WebClient — User-Agent masquerade (PublicUserAgent), URL via DownloadString
  • Tor — optional EnableTorPanel flag suggests onion-routed C2 fallback
  • Public IP check — PublicIpAddressGrab implies a geolocation or hosting-detection query

No mutex names, named pipes, or registry keys beyond persistence indicators were recovered.

Interesting Tidbits

  • Builder opsec: zero. Method names like EnableKeylogger, EnableClipboardLogger, VaultGetItem, and FtpPassword are stock AgentTesla builder defaults. No ConfuserEx, no SmartAssembly, no string encryption. This is either a test build or a lowest-tier MaaS customer.
  • Version-info masquerade: Claims to be Python 3.11.3 (64-bit) by Python Software Foundation, file description setup, internal name a GUID (f45b853c-c9d3-495e-9acb-d41a4a90029f.exe). The GUID also appears in the PE metadata as the internal filename — likely a builder-generated project ID.
  • Second GUID: $ac817265-7162-4840-9799-486144a753d9 appears in #Strings metadata — possibly a second builder project ID or a module GUID.
  • No wrapper, no loader: Unlike every other AgentTesla in this corpus, this sample is a direct .NET PE. This could indicate the builder was run in "direct output" mode (export compiled assembly) rather than "bundle with dropper" mode.
  • Floss failed: The floss.txt artifact shows a CLI argument parsing error, not decoded strings. The .NET metadata strings are already plaintext — floss had nothing to decode.
  • Capa false positives: Standard .NET DebuggerNonUserCodeAttribute etc. may trigger anti-debug signatures. Cross-reference with string evidence before trusting capa's anti-debug claims in isolation.

How To Mess With It (Homelab Replication)

Goal: Build a .NET Framework PE32 with comparable capa fingerprint for testing EDR/hunt rules.

Toolchain:

  • Visual Studio 2022 or dotnet build targeting .NET Framework 4.0+
  • C# console or WinForms project

Recipe:

  1. Create a C# project with references to System.Security, System.Drawing, System.Management, System.Net, System.Windows.Forms.
  2. Add P/Invoke imports for SetWindowsHookEx, CheckRemoteDebuggerPresent, VaultEnumerateVaults, BCryptOpenAlgorithmProvider, NtQuerySystemInformation.
  3. Implement classes named EnableKeylogger, EnableClipboardLogger, EnableScreenLogger, VaultEnumerateVaults, FtpHost, PublicIpAddressGrab.
  4. Use HttpWebRequest, FtpWebRequest, WebClient for network ops.
  5. Add RijndaelManaged or AesManaged crypto usage.
  6. Compile as PE32 (x86), GUI subsystem.
  7. Edit VS_VERSIONINFO resource to masquerade as Python 3.11.3 (64-bit).

Verification:

capa reproducer.exe

Expect hits for: keylogging, clipboard, screenshot, HTTP client, FTP send, Base64 encode/decode, AES encrypt/decrypt, DPAPI, registry query, process enumeration, WMI access, anti-debugger check, anti-VM strings.

Deployable Signatures

YARA Rule

rule AgentTesla_NakedDotNet_2024 {
    meta:
        description = "Naked .NET AgentTesla with builder-default unobfuscated method names"
        author = "PacketPursuit"
        date = "2026-07-30"
        hash = "6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb"
        confidence = "high"
    strings:
        $s1 = "EnableKeylogger" wide ascii
        $s2 = "EnableClipboardLogger" wide ascii
        $s3 = "EnableScreenLogger" wide ascii
        $s4 = "VaultEnumerateVaults" wide ascii
        $s5 = "VaultGetItem" wide ascii
        $s6 = "VaultOpenVault" wide ascii
        $s7 = "FtpHost" wide ascii
        $s8 = "FtpPassword" wide ascii
        $s9 = "PublicIpAddressGrab" wide ascii
        $s10 = "MozillaBrowserList" wide ascii
        $s11 = "ChromiumBrowserList" wide ascii
        $s12 = "StartupRegName" wide ascii
        $s13 = "AppAddStartup" wide ascii
        $s14 = "HideFileStartup" wide ascii
        $s15 = "EnableTorPanel" wide ascii
        $s16 = "CheckRemoteDebuggerPresent" wide ascii

        $dot1 = "System.Security.Cryptography" wide ascii
        $dot2 = "System.Drawing" wide ascii
        $dot3 = "System.Management" wide ascii
        $dot4 = "System.Windows.Forms" wide ascii
        $dot5 = "System.Net" wide ascii

        $bcrypt = "BCryptOpenAlgorithmProvider" wide ascii
        $dpapi = "ProtectedData" wide ascii

    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI
        and pe.imports("mscoree.dll", "_CorExeMain")
        and 6 of ($s*)
        and 3 of ($dot*)
        and any of ($bcrypt, $dpapi)
}

Sigma Rule

title: AgentTesla .NET Infostealer Execution Detection
status: experimental
description: Detects execution of AgentTesla .NET infostealer with builder-default method names and surveillance toolkit
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - CommandLine|contains:
            - 'EnableKeylogger'
            - 'EnableClipboardLogger'
            - 'EnableScreenLogger'
            - 'VaultEnumerateVaults'
            - 'VaultGetItem'
            - 'VaultOpenVault'
            - 'PublicIpAddressGrab'
            - 'MozillaBrowserList'
            - 'ChromiumBrowserList'
        - ImageLoaded:
            - '*\vaultcli.dll'
        - CommandLine|contains:
            - 'SetWindowsHookEx'
            - 'WH_KEYBOARD_LL'
    filter:
        Image|endswith:
            - 'devenv.exe'
            - 'msbuild.exe'
    condition: selection and not filter
falsepositives:
    - Legitimate security research tools using identical method names
    - Penetration testing frameworks
level: high

IOC List

Indicator Type Notes
6bd7207841fad8f065ae5ea7f71082e4625ebbacbfbd5c836c88a12024c379fb SHA-256 This sample
00c4222201ab023c32637707d091e643 MD5
f45b853c-c9d3-495e-9acb-d41a4a90029f GUID Internal filename / builder project ID
$ac817265-7162-4840-9799-486144a753d9 GUID Secondary metadata GUID
EnableKeylogger String Builder-default method name
EnableClipboardLogger String Builder-default method name
VaultEnumerateVaults String Windows Vault API call
PublicIpAddressGrab String IP resolution routine
StartupRegName String Registry persistence indicator
EnableTorPanel String Optional Tor C2 flag
MozillaBrowserList / ChromiumBrowserList String Browser targeting

Behavioral Fingerprint Statement

This binary is a .NET Framework PE32 compiled with MSVC 11.0, GUI subsystem, three sections, and imports only mscoree._CorExeMain. It carries unobfuscated CLR metadata with method names matching AgentTesla builder defaults (EnableKeylogger, EnableClipboardLogger, VaultEnumerateVaults, FtpHost, PublicIpAddressGrab). At runtime it installs a global low-level keyboard hook (SetWindowsHookEx + WH_KEYBOARD_LL), monitors clipboard changes (SetClipboardViewer), captures screenshots (CopyFromScreen), enumerates Windows Vault credentials (vaultcli.dll), queries WMI for system information, and exfiltrates via FTP (FtpWebRequest) and HTTP (WebClient/HttpWebRequest). It checks for debuggers (CheckRemoteDebuggerPresent) and references anti-VM strings. Persistence is attempted via registry Run keys and startup directory placement. No packing or obfuscation is applied.

Detection Signatures

capa → MITRE ATT&CK mapping:

capa Capability ATT&CK Technique
log keystrokes via application hook T1056.001
log keystrokes via polling T1056.001
capture screenshot T1113
read clipboard data T1115
create HTTP request / send request in .NET T1071.001
send file using FTP T1041
check for debugger via API T1622
reference anti-VM strings T1497.001
query environment variable T1082
query or enumerate registry key/value T1012
enumerate processes T1057
access WMI data in .NET T1047
decode data using Base64 in .NET T1140
encrypt/decrypt data via BCrypt / AES via .NET T1573
bypass Mark of the Web T1553.005
set global application hook T1056.001
get graphical window text T1010
get keyboard layout T1082
get system information on Windows T1082
get OS version in .NET T1082
create process in .NET T1059.003
terminate process T1489
suspend thread T1055

References

Provenance

  • Static analysis performed on 2026-07-30 using file, exiftool, pefile, strings, capa v7, binwalk, radare2 (CIL analysis), and manual grep inspection.
  • CAPE sandbox detonation skipped — no Windows guest available.
  • floss tool failed with argument-parsing error; .NET metadata strings are already plaintext.

^[sample 6bd72078/file.txt] ^[sample 6bd72078/pefile.txt] ^[sample 6bd72078/strings.txt] ^[sample 6bd72078/capa.txt] ^[sample 6bd72078/binwalk.txt] ^[sample 6bd72078/rabin2-info.txt] ^[sample 6bd72078/exiftool.json] ^[sample 6bd72078/triage.json]