SampleCheck5000, also known as SC5k, is a lightweight C#/.NET downloader associated with the Iranian cyberespionage actor OilRig, including activity tracked under the Lyceum subgroup. It was used in campaigns against previously compromised organizations in Israel, including entities in healthcare, manufacturing, and local government. The malware is part of OilRig’s broader pattern of abusing trusted Microsoft cloud services to blend command-and-control and exfiltration traffic with normal enterprise activity.
SampleCheck5000 interacts with a shared Microsoft Exchange or Microsoft 365 mail account and uses the Microsoft Office Exchange Web Services API as its primary communications channel. It retrieves commands and additional payloads from draft messages and attachments stored in the actor-controlled mailbox, and can execute downloaded OilRig tools on compromised hosts. Later variants expanded its handling of command and exfiltration workflows, including the use of message metadata to distinguish actions.
The malware can collect command output, store it locally in encrypted and compressed form, and then exfiltrate it through the same mailbox-based channel. It can also gzip-compress files before uploading them to the shared mailbox for operator retrieval. This design supports low-profile post-compromise operations while reducing the need for dedicated attacker infrastructure.
Observed use indicates a role as a downloader within persistent espionage operations rather than as a full-featured backdoor. SampleCheck5000 shares tradecraft with other OilRig tooling that leverages cloud-hosted services for covert communications and data theft, and reflects the group’s continued preference for mailbox- and API-based command channels in Middle East-focused intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...there are cases reported with the SC5k malware using Office 365 drafts...
ESET researchers analyzed a growing series of OilRig downloaders... These lightweight downloaders, which we named SampleCheck5000 (SC5k v1-v3)... are notable for using... Microsoft Office Exchange Web Services (EWS) API.
ESET researchers analyzed a growing series of OilRig downloaders... These lightweight downloaders, which we named SampleCheck5000 (SC5k v1-v3)... are notable for using... Microsoft Office Exchange Web Services (EWS) API.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as using Office 365 drafts for command-and-control, presented as behavioral context for the attribution discussion.
Malware cited as using Office 365 drafts for command-and-control.
... SampleCheck5000 ... (v1.0→v1.1) ...
SampleCheck5000 (v1.0→v1.1)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.