Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Palo Alto Networks has observed a recent high-threat spam campaign that is serving malicious macro documents... First, victims are presented with an email... The majority of these emails contain specific information about the victim’s company... which in turn may lead to a higher number of opened attachments.
This macro will invoke the WMI service to spawn a hidden instance of powershell.exe
The downloaded file is a PowerShell script that contains shellcode, which is subsequently decoded and executed | This macro will invoke the WMI service to spawn a hidden instance of powershell.exe with the following arguments... DownloadString(...) | iex
The payload proceeds to perform reconnaissance against the victim host by executing an ‘ipconfig -all’ in a new process... Additionally, the malware will take the output of the ‘net view’ command
it will return an encrypted DLL. This DLL can be decrypted using the same decryption previously discussed
This DLL is then temporarily written to disk in the following location: %%userprofile%%\\AppData\\LocalLow\\[random].db
After being written to disk, it will be executed using a call to rundll32.exe. The exported function of ‘Register’ is used when loading this malicious DLL.
the payload performs a number of actions in an attempt to determine if it is running within a virtualized environment or sandbox. Examples include looking for the following usernames... The payload also checks for the presence of the following libraries... Other simple checks, such as a call to IsDebuggerPresent(), are also performed.
Additionally, the malware will take the output of the ‘net view’ command and look for the absence of the following strings...
The payload proceeds to perform reconnaissance against the victim host by executing an ‘ipconfig -all’ in a new process and inspecting the results.
the payload performs a number of actions in an attempt to determine if it is running within a virtualized environment or sandbox. Examples include looking for the following usernames... The payload also checks for the presence of the following libraries... Other simple checks, such as a call to IsDebuggerPresent(), are also performed.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another malware family using the same LCRNG constants.
A fileless, memory-resident malware delivered via malicious Word macros and PowerShell. It performs anti-analysis checks, host reconnaissance, identifies potentially interesting victims such as POS and financial-transaction systems while avoiding healthcare and education environments, then contacts C2 to retrieve an encrypted DLL payload executed via rundll32.
Referenced as a code source: Seduploader’s updated hashing algorithm is described as being very similar to PowerSniff’s implementation (i.e., code reuse/inspiration), rather than PowerSniff being deployed as a payload in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.