Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Macros which was getting more obfuscated for anti-analysis lead to download Ursnif
If the flag is ‘RX’, it means the environment supports VBScript... it uses {3F4DACA4-160D-11D2-A8E9-00104B365C9F} as rclsid and {3F4DACB0-160D-11D2-A8E9-00104B365C9F} as riid to get the IRegExp2 interface pointer for the vbscript check.
Its data-sharing mechanism is enabled by implementing the memory-mapped files that the system paging file stores... At first, it calls CreateFileMapping with INVALID_HANDLE_VALUE as hFile and a hard-coded name... The bigger view is the container of the configuration file; the other is the storage for the C&C response.
The subroutine injected into winlogon.exe is a process that monitors and modifies the registry to make sure the bot survives after reboot... it will modify it and make sure it does.
It modifies the registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe\Debugger to point to the dropped file. The technique used here is called the ‘Image Hijack’.
If the OS is 64-bit, it creates the process: %ProgramFiles%\Internet Explorer\iexplore.exe, then injects it... it calls DuplicateHandle to duplicate the handle to the current process and then injects the malicious code into csrss.exe... Before it calls CreateRemoteThread to run the injected code... | Before it calls CreateRemoteThread to run the injected code, it inserts an argument into the memory space of the targeted process...
It modifies the registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe\Debugger to point to the dropped file. The technique used here is called the ‘Image Hijack’.
4 sophisticated methods for anti-analysis 1. Multi Obfuscations →Multi usage of Invoke-DOSfuscation/Invoke-Obfuscation
If the OS is 64-bit, it creates the process: %ProgramFiles%\Internet Explorer\iexplore.exe, then injects it... it calls DuplicateHandle to duplicate the handle to the current process and then injects the malicious code into csrss.exe... Before it calls CreateRemoteThread to run the injected code... | Before it calls CreateRemoteThread to run the injected code, it inserts an argument into the memory space of the targeted process...
Therefore, a conventional signature-based virus scanner would fail to find any infection by scanning the hard disk.
As soon as the system is infected by Bebloh, the malware is injected into explorer.exe and the original executable file that contains Bebloh is deleted.
4. Check Execution Environment (only works Japanese environment) →Get-Culture
The focus of this bot is to steal money from targeted financial institutions and hide the transactions from the victim... This configuration file contains the URLs of the targeted financial institution, request mask templates, HTML injecting templates and other information that is used by the hooked APIs to make fraudulent transactions and create fake transaction logs.
The subroutine injected into svchost.exe is responsible for the communication between the victim’s PC and the C&C server... It sends an initial message to the C&C servers in its hard-coded list... If the response is ‘>UD [update file URL]’, it will update itself with the new file...
If the response is ‘>UD [update file URL]’, it will update itself with the new file... '>CV 15 >DI INJECTFILE [File Size] [Configuration File]' – downloads the configuration file.
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
The hooked subroutine contains the core functions for masking domain URLs, modifying received messages and altering sending messages... InternetReadFile have the ability to filter out or alter the received data... HttpSendRequestA, modify the sending message according to the configuration file.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A banking Trojan that spies on user data and uses updated AV-evasion and persistence techniques. It injects into explorer.exe, deletes the original executable from disk, remains memory-resident during runtime, and on shutdown writes itself back to disk and creates autostart via a .lnk file with a randomized filename.
Banking trojan associated with Avalanche; infections in Germany shared command-and-control infrastructure with Ransomlock.
Banking trojan associated with Avalanche; infections in Germany helped investigators identify shared infrastructure.
Downloader malware used by Group-A to fetch and deliver Ursnif, including encrypted Ursnif binaries from Bebloh C2 infrastructure. Also noted as capable of delivering Pushdo.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.