Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
XLS-to-DBatLoader-or-GuLoader-for-AgentTesla-variant — CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE | Kitploit
Tools/GitHubGitHub/blackoclock/xls-to-dbatloader-or-guloader-for-agenttesla-variant
ExploitationNetwork ForensicsSteganographyMalware AnalysisDigital ForensicsCommand and ControlThreat Intelligence
GitHubblackoclock/xls-to-dbatloader-or-guloader-for-agenttesla-variant

XLS-to-DBatLoader-or-GuLoader-for-AgentTesla-variant

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE

View Repository
286 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

THE ANALYZED FILE

PCAP-Based Analysis | Date: 2025-03-12 | Author: BlackOclock

TABLE OF CONTENTS

1. ANALYSIS OVERVIEW

  • 1.1 The Analyzed File (PCAP Only)
  • 1.2 Infection Timeline & CVE Mapping

2. NETWORK TRAFFIC ANALYSIS

  • 2.1 Protocol Hierarchy – Big Picture
  • 2.2 Conversations – Top Talkers & Data Transfer
  • 2.3 Endpoints – Tx/Rx Confirmation
  • 2.4 HTTP Export Objects – Extracted Files
  • 2.5 HTTP Contains Filter – Steganography Check

3. NETWORKMINER ANALYSIS

  • 3.1 Extracted Files Overview
  • 3.2 File Details (HTA, VBS, TXT)
  • 3.3 JA3 / JA3S /JA4 Fingerprints

4. ZEEK (ZUI) LOGS ANALYSIS

  • 4.1 File Extraction Confirmation
  • 4.2 MD5/SHA1 Hashes & Timestamps
  • 4.3 VirusTotal Integration

5. EXTRACTED FILES & STATIC ANALYSIS

6. TRIAGE & BEHAVIORAL ANALYSIS

  • 6.1 HTA Triage – mshta.exe Execution
  • 6.2 VBS Triage – WScript.exe & PowerShell
  • 6.3 TXT Triage – Notepad.exe & Ransomware Behavior

7. PROCESS INJECTION ANALYSIS

  • 7.1 Process Tree – mshta → cmd → powershell → csc → Notepad
  • 7.2 WriteProcessMemory Events
  • 7.3 Token Manipulation (SeDebugPrivilege)

8. MEMORY DUMP ANALYSIS

  • 8.1 PowerShell Memory Dumps (HTA) (PID 4424)
  • 8.2 comonstraints.vbs Memory Dump (PID 1184)

9. C2 DETECTION & FINGERPRINTING

  • 9.1 Jarm / JA4 Analysis
  • 9.2 GreyNoise & Shodan Pivoting & C2 Infrastructure Mapping

10. EXFILTRATION ANALYSIS

  • 10.1 FTP Traffic – 89.39.83.184
  • 10.2 Stolen Credentials & Contact Lists

11. RANSOMWARE BEHAVIOR

  • 11.1 foeMMBIG.txt Execution
  • 11.2 Notepad.exe as Injection Target

12. THREAT INTELLIGENCE

  • 12.1 VirusTotal & MalwareBazaar Results
  • 12.2 MITRE ATT&CK Mapping
  • 12.3 APT37 (ScarCruft) Correlation

13. DETECTION ENGINEERING

  • 13.1 Sigma Rules

14. CONCLUSION & IOCs

  • 14.1 Full Attack Chain Summary

  • 14.2 Indicators of Compromise (IPs, Hashes, Domains)

  • 14.3 Recommendations

                                         NOTE!!! In this analysis, 'JUST' PCAP file was used! ZIP files weren't needed;
    

##1. ANALYSIS OVERVIEW

Malware-Traffic-Analysis.net Source Files

Shape 1: downloaded source files in malware-traffic-analysis.net - 'JUST' PCAP file was used\

2025-01-09 (THURSDAY): CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE

##2. NETWORK TRAFFIC ANALYSIS

2.1-Protocol Hierarchy – Big Picture

Protocol Hierarchy

I started with Protocol Hierarchy to get a big-picture view of the traffic. This shows the volume of each protocol used. As shown in the figure, TLS accounts for 82.4% of all traffic. Additionally, Media Line and Line-Based data are also present. However, to better understand the network activity, we need to examine Conversations and Endpoints.

2.2-Conversations – Top Talkers & Data Transfer

Conversations

We use Conversations to detect IP pairs that have the most data transfer between them. The analysis shows that 10.9.1.101 (host) and 104.17.201.1 have the highest traffic volume. Ports 80 and 443 were used for this data transfer. Additionally, we see that 3 MB of data was transferred to 10.9.1.101 (host) from 104.17.201.1. Another critical finding is the connection on 21 port cause of the connection from the WAN IP (89.39.83.184), which suggest potential exfiltration. But we are not sure now, cause we don't know yet about it. We need a proof!

2.3- Endpoints

Endpoints

We use Endpoints to identify the top talkers on the network. 104.17.201.1 has 3MB of transmitted data (Tx) and also 10.9.1.101 has 3MB of received data (Rx). Additionally, the top talkers are 104.17.201.1 as the source and 10.9.1.101 as the destination.

2.4- HTTP Export Objects

Export

Export is used to identify files,data,emails, etc. transferred over the network. Everytime,when we analyze pcap, we should just check here to see which packets contain which data. Well we noted 88,132,2457 and 2468 packets.

2.5- HTTP Contains Filter

Export

If there is a http protocols on the network. We should check png,zip,jpg,jpeg ( Steganography ) as a media on filter, Cause attackers often use malicious codes on media files to bypass antivirus detection.

#Example: http contains ".png" or http contains ".jpg" or http contains ".jpeg" or http contains ".zip"

Just we are seeing why this filter is important,when 80 port is used on the network. in here there is a .hta which is sended on media files at 47 packet. But when we use export to identify files,there wasn't.

##3. NETWORKMINER ANALYSIS

  • 3.1 File Details (HTA, VBS, TXT)

Networkminer

We can use networkminer to identify faster on PCAP. If you use REMnux or Linux system , you can write on terminal ( networkminer pcap_name )

Frame = 47 Filename= seemebestthingsevermeetgivenbestthingsfornewways | Extension = .hta | Size = 47 KB | Source IP = 192.3.27.144 Frame = 132 | Filename= comonstraints | Extension = .vbs | Size = 223 KB | Source IP = 107.172.31.5 Frame = 2457 | Filename = foeMMBIG | Extension = .txt | Size= 325 KB | Source IP = 107.172.31.5

  • 3.2 JA3 / JA3S /JA4 Fingerprints

Networkminer JA4/JA3

JA3 Hashes:

  • 06843d66057fc9cbe42e9d690308903 (Frame 8)
  • 62136a81b5b727d039d8160d188863aa (Frame 14)
  • 3c4eb72b882d4d1442c67ce73f1292a9 (Frame 140)

JA4 Fingerprints:

  • t13d1516h2_8daaf6152771_02713d6af862
  • t13d201000_2b729b4bf63_29829a46703f

Well, but why we need JA4 and JA3 Hashes ? There can be a question what is JA3 and JA4?

Let me explain; JA3 and JA4 are techniques used to fingerprint TLS clients and servers based on the parameters of the TLS handshake.JA3 creates an MD5 hash of the TLS handshake's client hello packet, uniquely identifying the client application (e.g., browser, malware).

JA4 is a newer technique.It is like a fingerprint for internet traffic. Just like humans have unique fingerprints, every software that connects to the internet leaves a unique mark. More helpful to find C2 server.

##4. ZEEK (ZUI) LOGS ANALYSIS

  • 4.1 File Extraction Confirmation, MD5/SHA1 Hashes & Timestamps , VirusTotal Integration

Zeek logs were used to verify the extracted files from HTTP traffic. The files.log shows the following entries:

These hashes were later used for VirusTotal lookups.

hta Result

Hta (seemebestthing…)

MD5 e90ae8ec16ea2056caaa64ac13a31373 SHA1 8041abda3769b97d8e8b980c6a77fcd2829d715 SHA256 df215a01f6a83014a148c6e407cdc8422e9119a88b4220a1321b2986ea9aef63

vbs result

Download Tool