Agent Tesla IOC Feed

Agent Tesla is an advanced malware that primarily serves as a keylogger, capturing and transmitting sensitive data such as usernames and passwords by monitoring keystrokes on an infected computer. In addition to keylogging, it can take screenshots, extract credentials from various software, and even act as a remote access tool for cybercriminals. This malware is notorious for its versatility, including the ability to exfiltrate data through multiple channels such as FTP, email, and Telegram, making it particularly effective at bypassing standard security measures.

First identified around 2014, Agent Tesla has continuously evolved, becoming more adept at evading detection and increasing its functionality. It is commonly spread through phishing emails, malicious attachments, or compromised websites. The ease of customization and adaptability of Agent Tesla make it a preferred choice among cybercriminals, posing a significant threat in cybersecurity.

Below you will find the most recent Agent Tesla Indicators of Compromise (IOC’s) from our Threat Intelligence Feed. In addition to the data below, our private Agent Tesla IOC feed contains additional data including C&C information. Please note the data below is intentionally delayed by 48 hours. For live data updated every minute, please sign up for a free trial.

Latest Agent Tesla IOCs

URL / IP / MD5 Date Added
http://raziritop.org/ngqwpl/ngown.exe 2024-10-26 11:50:05
http://87.120.84.38/txt/UyIkxZbgRRPlkjH.exe 2024-10-24 05:40:06
http://192.3.101.157/550/wlanext.exe 2024-10-23 11:30:06
https://api.telegram.org/bot1833231669:AAGi09Fqux60ktahLhT8D677G7uISE3okog/sendDocument 2024-10-12 18:59:24
https://api.telegram.org/bot6920956123:AAF5MVKcRQXhI4WbvmFoIFU5yl4eW32KEn4/ 2024-08-06 02:26:07
https://api.telegram.org/bot7390139954:AAFw-89dzufZnN9iQ-qMJ7xuGsXRrzvXAEI/ 2024-07-28 20:43:14
http://198.46.174.139/71/winiti.exe 2024-07-26 05:18:09
http://198.46.174.139/xampp/ezm/ez/somethinggreatwithmeentiretimegetmebackthingsgreatgoinggreatthignseverwewhichamazingthings___________reallygreatthingseverhappened.doc 2024-07-26 01:08:20
http://198.46.174.139/55/winiti.exe 2024-07-25 01:08:04
https://198.46.174.139/55/winiti.exe 2024-07-25 01:07:57

Ready to see all of our data?

If you’re ready to take a look at our full set of data, click below to start your 15-day Free Trial.