Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Функционал червя ВПО получает список съемных носителей. В корне файловой системы носителя создается копия ВПО с именем Sys.exe . Автозапуск реализован при помощи файла autorun.inf .
Недавно центр круглосуточного реагирования на инциденты информационной безопасности CERT Group-IB зафиксировал необычную фишинговую рассылку... Под видом вложения в таком вот письме содержалась картинка, при клике на которую пользователь попадал на сайт cdn.discordapp.com, и оттуда загружался вредоносный файл.
During this execution we may encounter scripts typically started by wscript running a cmd followed by a powershell, or directly a powershell, which will attempt either to download the next stage or to deobfuscate/decrypt the binary
Создается файл %AppData%\GFqaak\WinDriv.url, запускающий Zpzwm.exe .
These include archives (ZIPs or RARs) as well as scripts written in different languages (JS, VBS, etc.).
These include archives (ZIPs or RARs) as well as scripts written in different languages (JS, VBS, etc.).
С помощью FranchyShellcode осуществляется инжект полезной нагрузки в процесс [inj-replace] ... Была найдена функция, отвечающая за подгрузку и инжект в процесс msiexec.exe произвольного модуля.
Исходный файл защищен при помощи EaxObfuscator... Полезная нагрузка хранится в ресурсах загрузчика AtProtect в виде Bitmap-картинок... Данные закодированы Base64 и зашифрованы AES.
one where we have obfuscated code that works at runtime, or, alternatively, images in resources that also work at runtime using steganography techniques.
При наличии соответствующего флага ВПО может запустить скрытый процесс iexplorer...
С помощью FranchyShellcode осуществляется инжект полезной нагрузки в процесс [inj-replace] ... Была найдена функция, отвечающая за подгрузку и инжект в процесс msiexec.exe произвольного модуля.
После отправки папка 404k удаляется. ... Возможность выполнить удаление текущего файла. ... Самоуничтожение
it can use other legitimate processes that are commonly related to .NET (csc.exe, applaunch.exe, installutil.exe, etc.)
their main goal is usually to deobfuscate code and launch the next version or to download the next stage
Проверка нахождения в виртуальной среде ... поиска процессов vmtoolsd, VGAuthService, vmacthlp, VBoxService, VBoxTray. Если найден хотя бы один, ВПО завершает работу. ... Демонстрация диалоговых окон различных типов Может быть использовано для обхода некоторых песочниц.
[TA0007][T1049] System Network Connections Discovery
Searching for common processes in virtualized machines or names of analysis tools
Далее следует информация о системе: ... IP: {Внешний IP} Owner Name: {Имя компьютера} OS Name: {Название ОС} OS Version: {Версия ОС} OS PlatForm: {Платформа} RAM Size: {Размер ОЗУ}
Проверка нахождения в виртуальной среде ... поиска процессов vmtoolsd, VGAuthService, vmacthlp, VBoxService, VBoxTray. Если найден хотя бы один, ВПО завершает работу. ... Демонстрация диалоговых окон различных типов Может быть использовано для обхода некоторых песочниц.
Keylogger Период отправки лога: 30 минут. Поддерживаются все символы. Спецсимволы экранируются. Есть обработка клавиш BackSpace и Delete.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET Stubs: Sowing the Seeds of Discord (PureCrypter) Aberebot AbstractEmu AdoBot 404 Keylogger Agent Tesla Amadey AsyncRAT Ave Maria BitRAT BluStealer Formbook LimeRAT Loki Password Stealer (PWS) Nanocore RAT Orcus RAT Quasar RAT Raccoon RedLine Stealer WhisperGate
Keylogger malware included among the analyzed malware samples in the blog post.
Windows malware family combining keylogging and password-stealing capabilities. It is delivered via phishing, uses loaders including AtProtect, can persist via Run keys and URL launchers, exfiltrates data over SMTP/FTP/Pastebin, captures keystrokes, clipboard contents, screenshots, and passwords, and includes basic anti-analysis and UAC-bypass features.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.