Cyber Defenders - AgentTesla Writeup
Category: Malware Analysis
Checkout the lab here: https://cyberdefenders.org/blueteam-ctf-challenges/agenttesla/
Description
As a malware analyst at CyberResponse Inc., you are tasked with investigating a piece of malware that has been reported to steal sensitive information like passwords, keystrokes, and screenshots. Your goal is to dissect the malware sample, understand its components, and uncover its attack methods. This task is crucial for developing countermeasures to protect users and organizations.
Q1: Identifying the scripting engine or interpreter used in malware can provide insights into its functionality and potential behaviors. What is the name of the scripting engine embedded in this executable?
To identify the scripting engine embedded in the provided malware, I started my analysis by using Detect It Easy (DIE).
AutoIt is a free scripting language for Windows. Its syntax is very simple and quite similar to BASIC.
Over time, AutoIt has evolved significantly and can interact deeply with the operating system (calling Windows APIs). Although AutoIt itself is legitimate and useful software, it has become a favorite tool for hackers because:
- Easy to learn and write
- Obfuscation capabilities
When DIE scans the file, it reads the external structure and immediately recognizes it as a program compiled with C/C++ (which is the interpreter wrapper). However, thanks to its signature scanning, DIE detects that inside this wrapper, there is AutoIt formatted data.
Answer: AutoIt
Q2: Determining the hash of executable components is essential for verifying integrity and identifying malware. When the malware is executed, there are scripts running, one of them is a bin file. What is the MD5 hash of this file?
Because the file is packed with UPX, I had to unpack it first:
1
& "C:\Users\Administrator\Downloads\Tools Main\Tools\upx-4.2.4-win64\upx.exe" -d DHL008976.exe -o unpacked.exe.dat
The challenge mentions using the AutoIt Extractor, so I tried using it with the newly unpacked file.
Looking at the resources section, I can see:
>>>AUTOIT SCRIPT<<<: This is the original source code of the malware, written in AutoIt.>>>AUTOIT NO CMDEXECUTE<<<: This is an AutoIt compiler configuration flag, likely to prevent the terminal window from showing.agelessandbrawlysmight be additional data files, configuration files, or secondary payloads embedded by the attacker into the main file. The AutoIt Script above probably contains commands to extract or call these files when it runs.
Saving everything to the Desktop, when I check the AutoIt script file, I see that this file is heavily obfuscated and very hard to read. However, I can still see the action of attaching external files inside the executable during compilation, decrypting them, and then dropping the files.
Checking both ageless and brawlys files, I found that ageless is the binary file mentioned in the challenge. I used the certutil tool to get the hash of this file:
1
certutil -hashfile .\ageless.bin md5
Answer: a657189456d164a28b0eb9f5a2654b26
Q3: Recognizing key methods in the malware’s code helps to pinpoint its main functionalities. What is the name of the method that has main logging functionalities, such as keylogging and screen logging?
Through the AutoIt script read from the previous question, I learned that the malicious process was decrypted and injected into RAM.
Using PE-sieve to capture the executable’s runtime behavior, I ran the DHL008976 file and monitored the processes appearing in Task Manager or Process Hacker.
This is what I filtered from pe-sieve after running the malware for about 3-4 minutes.
- Files like
12a0000.DHL008976or72aa0000.clr.dllare named following the rule: [Hex Memory Address].[Module Name]. - The
.tagfiles are small attached text files containing details about why PE-Sieve suspected and extracted the corresponding memory region. - The Report files (dump_report, scan_report) are summary reports in JSON and plain text formats, recording the entire scanning process, the number of infected modules, and the techniques used by the malware.
Let’s check the suspected files.
When the AutoIt malware executes, it extracts itself into RAM to prepare for the next code injection steps. So this seems to be just a copy of the original malware file.
Continuing to check the file dumped at the default base address 400000. The result shows that this is an executable compiled with C/C++, this is probably the data that the AutoIt code above extracted from the remaining files and loaded into the 400000 location.
To explain further, inside a PE file, there is a .rsrc section used to store resources like icons, images, sounds, etc. DIE scans the signatures and notices that instead of containing the aforementioned resources, it contains executable code written in BASIC.
This is the BASIC code that appears to have been dropped from the previous file, located at memory region 7370000 named DHL008976.
DIE displays Language: BASIC and Compiler: VB.NET.
VB.NET (Visual Basic .NET) is a programming language developed by Microsoft. Although it inherits the syntax of the old BASIC/Visual Basic language, it is built on the .NET Framework.
With languages like C or C++, when programmers compile, the source code is translated directly into machine code for the computer’s CPU to understand and run directly. But languages in the .NET family (including C#, VB.NET, F#) operate differently. They are all translated into a single common language called IL - Intermediate Language.
Only when you double-click to run that .exe file on your computer, the .NET Framework on your machine translates that IL into machine code to run.
I will use a tool called dnSpy to inspect this file. Because the structure of IL is very clear and retains almost all logic, variable names, and original function names, dnSpy can easily decompile that IL file back into readable source code.
Of course, hackers wouldn’t let you easily read it, they obfuscated this file. Here the Namespaces are just random names.
I tried pressing Ctrl+Shift+K and searching for the keyword “Keylog”, limiting the search scope to the file being analyzed.
The tool returned important results, highlighting the _keyLogger field.
Tracing back from the search results, I identified that the main method controlling these execution flows is asQXUhiK0j() belonging to the class Rj1, namespace 6FnwkW9.
→ This is the method containing the malware’s main keylogging and screen capturing functionalities.
Answer: asQXUhiK0j
Q4: Understanding the output format of keylogging functionalities assists in tracing and decoding captured data. What is the specific format (programming language) for the output of the malware keylogging functionality?
As known, the method asQXUhiK0j() belonging to class Rj1 contains the keylogging and screen capturing functionality. Let’s look at this whole Rj1 class a bit broader. Rj1 is declared as a public static class; it exists uniquely and throughout from when the malware runs until it is terminated.
This class contains the mastermind method asQXUhiK0j(). Instead of letting the malware run chaotically, class Rj1 plays a logic coordinating role:
- Reading the hacker’s configuration settings
- Checking the current environment
- Initializing data stealing modules to operate at the right time.
- …
If we scroll down to the very end of the Rj1 class, we will see the declaration private static I7FH _keyLogger;. This is the variable used to store the Keylogger feature management object.
Looking back inside the method asQXUhiK0j(), although obfuscated by changing the order of statements with if else, we can still see the function initializes a new _keyLogger object and runs its 6PN() method.
I am not sure what 6PN() does, but I can infer that this new _keyLogger object probably possesses methods to log the keyboard and perhaps also other methods to format the keylogging output.
To confirm this hypothesis, I double-clicked on the I7FH class to check. At a glance, this class performs exactly the function I thought; I won’t go deep into explaining everything but I will point out what gives us the answer to the question.
If you browse through this class, you will encounter methods used to format the output like here I have 9R5eFu(), where you can immediately see:
- A piece of code assigning line break tags through the command this.KeylogText += “
<br>”. - Another piece of code calling string.Concat to concatenate strings. The current window title and system timestamp (DateTime.Now.ToString()) are carefully wrapped inside
<b>,</b>tags and ending with<br>.
→ The appearance of <b>, <br>, <hr> tags provides evidence that the keylogging functionality formatted the output data in HTML.
Answer: html
Q5: Knowing the exfiltration methods used by malware is crucial for identifying data breaches and protecting sensitive information. What is the full URL the malware uses for exfiltration of data using Telegram?
It could take a while to discover this completely blind by looking around everything in this file, or maybe using other methods, I believe so. But since the challenge has already hinted at it, let’s cut to the chase here.
Searching for the keyword Telegram, I can see this URL immediately.
Answer: https://api.telegram.org/bot6900973449:AAF8wx9iUPZvdsBE34vKz_RL7sCyp2owiPA/
Q6: To better understand the persistence strategies of the malware, can you provide the name of the file that was dropped by the malware as part of its persistence mechanism?
At this stage, I had to dynamically analyze this malware file, using ProcMon to record the behavior of the malware file.
After it finished running, I used the filter feature (Ctrl+L) to see what files the process dropped.
Perhaps this is the payload for other behaviors, specifically persistence.
Answer: DHL8900067.vbs
Q7: Knowing the legitimate services abused by malware can aid in recognizing suspicious network activities. Which legitimate service does the malware use to get the public IP address of the victim?
Going back to dnSpy, if you are still where we found the telegram URL, scrolling up a bit you will see this link.
This service, ipify, is a well-known and legitimate API that provides the public IP address of a device making a request.
Answer: ipify
Q8: Understanding the anti-VM techniques used by malware is essential for bypassing detection in analysis environments. What is the function name used for the Anti-VM technique?
Remember when we analyzed asQXUhiK0j() (which coordinates launching the Keylogger and Screenlogger). In that code block, there is a highly suspicious conditional branch aimed at committing suicide if it detects an unsafe environment.
Finding the previous branch instruction when num == 3.
We see the if else check executing a call to an object returning a boolean type, let’s check this 8O7SbU object.
When delving into the structure of this class, at the first function, which is the function that the previous conditional statement used, Fqt(). I discovered a series of check methods including: tu9hDE(), B74fjj(), uPW(), oZp02y6(), and the final safeguard is inSP0fl62().
If any function among these 5 functions returns a true value, the code block will immediately return true to alert the external coordinator to proceed with self-destruction. Only when it passes everything does the function return false to allow other malicious modules to operate.
The previous methods function to:
- tu9hDE(): Check if the process is being attached by a debugger.
- B74fjj(): Check if the current IP address belongs to a server/cloud environment.
- uPW(): Check real-time execution speed to counter emulators.
- oZp02y6(): Check if Sandbox software libraries are injected into the process.
Only inSP0fl62() performs a WMI query to check the hardware configuration, thereby determining if the malware is running in a virtualized environment (VMware, VirtualBox).
Answer: inSP0fl62
Conclusion
Through static analysis with Detect It Easy (DIE) and AutoIt Extractor, followed by dynamic analysis with PE-sieve, dnSpy, and ProcMon, I successfully deconstructed the AgentTesla malware. The malware initially packed with UPX uses an AutoIt wrapper to decrypt and inject its core payload into memory. The core payload, written in VB.NET (compiled to Intermediate Language), was decompiled via dnSpy, revealing its main class (
Rj1) and method (asQXUhiK0j()) responsible for orchestrating keylogging and screen capturing.The analysis revealed the keylogging output is formatted in HTML, exfiltration is carried out via a Telegram Bot API, and persistence is achieved by dropping a
DHL8900067.vbsscript. Furthermore, the malware uses the legitimateipifyservice to determine the victim’s public IP address and implements extensive anti-VM/anti-analysis techniques, particularly theinSP0fl62function which queries WMI to detect virtualized environments.





























