SampleCheck5000, also known as SC5k, is a lightweight Windows downloader associated with the Iranian cyber-espionage actor OilRig, including activity tracked under the Lyceum subgroup. It has been used in operations targeting organizations in Israel, including healthcare, manufacturing, and local government entities, typically against networks that had previously been compromised.
SampleCheck5000 is implemented in C#/.NET and uses Microsoft Office Exchange Web Services to interact with a shared Microsoft Exchange or Office 365 mailbox controlled by the operator. Its command-and-control design relies on draft messages and attachments stored in that mailbox to retrieve commands and additional payloads, allowing malicious traffic to blend with legitimate enterprise cloud activity. Multiple victims may communicate through the same shared operator-controlled account.
The malware’s primary role is to download and execute additional OilRig tools, but later variants also support exfiltration through the same mailbox-based channel. Reported behavior includes retrieving command content and payloads from draft messages, accessing files for exfiltration, compressing uploaded data with gzip, and logging command output locally in encrypted and compressed form before transfer. Version evolution from early releases through later variants indicates ongoing development, including modularization and expanded exfiltration and command-handling logic.
SampleCheck5000 forms part of a broader OilRig tradecraft pattern of abusing trusted Microsoft cloud services for covert command-and-control and data theft, alongside related families such as OilCheck, ODAgent, and OilBooster. This approach supports persistence in previously targeted environments while reducing the visibility of attacker infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Utilisation de services Microsoft hébergés pour le C2 (RDAT via EWS, SC5k via Office 365 drafts, OilCheck via Graph/Outlook drafts)
ESET researchers analyzed a growing series of OilRig downloaders... These lightweight downloaders, which we named SampleCheck5000 (SC5k v1-v3)... are notable for using... Microsoft Office Exchange Web Services (EWS) API.
ESET researchers analyzed a growing series of OilRig downloaders... These lightweight downloaders, which we named SampleCheck5000 (SC5k v1-v3)... are notable for using... Microsoft Office Exchange Web Services (EWS) API.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as using Office 365 drafts for command-and-control, presented as behavioral context for the attribution discussion.
Backdoor cited as a comparison for using Office 365 drafts as a C2 channel.
Malware cited as using Office 365 drafts for command-and-control.
... SampleCheck5000 ... (v1.0→v1.1) ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.