Skip to main content
Mallory
MalwareUsed by 2 actors

ISMDoor

ISMdoor is a credential-stealing remote access trojan (RAT) associated in the provided reporting with the Iranian threat actor Greenbug and also listed as part of the OilRig malware arsenal. Arbor Networks assessed that Greenbug may have used ISMdoor to steal credentials on behalf of Shamoon operators, particularly against Saudi targets ahead of destructive Shamoon attacks. Reported capabilities include remote command execution, credential theft, likely Mimikatz execution, keylogging, and data exfiltration. Newer versions were described as shifting from HTTP-based command and control to a covert DNS-based channel, using DNS TXT records and AAAA/IPv6-related queries to create a bidirectional C2 path. In this scheme, data to the C2 is sent via specially crafted query names and data from the C2 is returned via IPv6 addresses; the bot drives all communications. Arbor reported commands including "CreateMimi1Bat," likely used to execute Mimikatz via PowerShell scripts ccd61.ps1 and Invoke-bypassuac, and "ExecuteKL," likely used to run a keylogger via Winit.exe and return a "Start Keylog Done" message to C2. The malware was also referenced in connection with watering-hole activity and 64-bit malware. A sample named WmiPrv.tmp with hash f5ef3b060fb476253f9a7638f82940d9 was submitted to VirusTotal from Iraq on 2017-10-15 and contained the PDB path C:\Users\Void\Desktop\v 10.0.194\x64\Release\swchost.pdb. Reported C2 domains included thetareysecurityupdate[.]com and securepackupdater[.]com. Additional reported infrastructure and related indicators included domains such as outbrainsecupdater[.]com, securelogicupdater[.]com, wixwixwix[.]com, biocatchsecurity[.]com, corticasecurity[.]com, covertixsecurity[.]com, arbescurity[.]com, ymaaz[.]com, winsecupdater[.]com, dnsupdater[.]com, winscripts[.]net, allsecpackupdater[.]com, lbolbo[.]com, oospoosp[.]com, osposposp[.]com, znazna[.]com, mbsmbs[.]com, benyaminsecupdater[.]com, and ntpupdateserver[.]com; IPs 151.80.113.150, 151.80.221.23, 217.182.244.254, 46.105.130.98, 5.39.31.91, and 80.82.66.164; hashes 37d586727c1293d8a278b69d3f0c5c4b, 82755bf7ad786d7bf8da00b6c19b6091, ad5120454218bb483e0b8467feb3a20f, e0175eecf8d31a6f32da076d22ecbdff, and f5ef3b060fb476253f9a7638f82940d9; and SSL certificate fingerprint 3b0b85ea32cab82eaf4249c04c05bdfce5b6074ca076fedf87dbea6b28fab99d.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Greenbug

On 15 October 2017 a sample of ISMdoor was submitted to VirusTotal from Iraq. The sample name was WmiPrv.tmp (f5ef3b060fb476253f9a7638f82940d9) and it had the following PDB string: C:\Users\Void\Desktop\v 10.0.194\x64\Release\swchost.pdb

via clearsky blogclearskysec.com
CHRYSENE

CHRYSENE ... CAPABILITIES: Watering holes, 64-bit malware, covert C2 via IPv6 DNS, ISMDOOR

via dragos blogdragos.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.001PowerShellEvidence1
TacticExecution

"...likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac)..." and "adversaries use DNS queries to carry out malicious PowerShell commands"

Credential Access

2 techniques
T1003OS Credential DumpingEvidence1

"One is 'CreateMimi1Bat'; which likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac)."

T1056.001KeyloggingEvidence1

"Another command is 'ExecuteKL'; which likely executes a keylogger (executes Winit.exe and sends 'Start Keylog Done' message back to the C2)."

Collection

1 technique
T1056.001KeyloggingEvidence1

"Another command is 'ExecuteKL'; which likely executes a keylogger (executes Winit.exe and sends 'Start Keylog Done' message back to the C2)."

T1071Application Layer ProtocolEvidence1

Two domains were used for command and control: thetareysecurityupdate[.]com securepackupdater[.]com

T1071.004DNSEvidence1

"Greenbug has shifted away from HTTP-based C2 communication with Ismdoor. It’s now relying on a new DNS-based attack technique... using DNS TXT record queries and responses to create a bidirectional command and control channel." Also: "custom covert channel using AAAA DNS queries for IPv6 addresses."

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

"Schwarz said using this technique, data is also be exfiltrated from the machines as well."

INDICATORS OF COMPROMISE

IOCs tracked for this family

22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
16 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
6 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app9 years ago
domain●●●●●●●●●●●●View more in app9 years ago
domain●●●●●●●●●●●●View more in app9 years ago
domain●●●●●●●●●●●●View more in app9 years ago
domain●●●●●●●●●●●●View more in app9 years ago
domain●●●●●●●●●●●●View more in app9 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching22

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.