Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware: GELUP bb5054f0ec4e6980f65fb9329a0b5acec1ed936053c3ef0938b5fa02a9daf7ee 6d15cd4cadac81ee44013d1ad32c18a27ccd38671dee051fb58b5786bc0fa7d3
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Gelup adds this shortcut file to the task scheduler by running the schetasks.exe command... schetasks.exe /create /rl highest /tn <RANDOM> /sc logon /tr C:\$Recycle.Bin\<RANDOM>\<RANDOM>.lnk
Gelup adds this shortcut file to the task scheduler by running the schetasks.exe command... schetasks.exe /create /rl highest /tn <RANDOM> /sc logon /tr C:\$Recycle.Bin\<RANDOM>\<RANDOM>.lnk
In case the user/account is Guest, Gelup copies itself into “%AllUsersProfile%\{RANDOM}.exe” and sets itself in the registry’s Run key.
After cleanup, Gelup creates the shortcut file “C:\$Recycle.Bin\<RANDOM>\<RANDOM>.lnk”, which is for C:\Windows \System32\ComputerDefaults.exe... it literally has a shortcut file binary in itself.
Gelup tries to bypass UAC by “mocking” trusted directories and using DLL side-loading... Gelup creates a directory named “C:\\Windows ”... creates a “System32” directory... copies a legitimate ComputerDefaults.exe... Finally, the renamed Gelup, as propsys.dll, will be successfully executed under the context of ComputerDefaults.exe without UAC dialog.
Gelup resolves most Windows application programming interfaces (APIs) by using the hash just before calling it... the strings in Gelup’s code are decrypted at runtime... using AES256-ECB... The second method uses XOR and Bit-shift for stack values.
Threat Actors make use of packers when distributing their malware as they remain an effective way to evade detection and to make them more difficult to analyze.
It starts by storing some strings in the stack that will use to find the Windows APIs needed to unpack itself: VirtualAlloc, VirtualProtect, LoadLibraryA, VirtualFree and VirtualQuery.
Gelup tries to bypass UAC by “mocking” trusted directories... create a directory named “C:\\Windows ”... copies itself into the trailing spaced directory and renamed as “propsys.dll”.
Download an executable from a specific URL and save it in %temp%\<RANDOM>.exe, then execute and delete it... Delete self by using bat file... Gelup... deletes the original file and tmpaddon_bak.
Second stage Unpacks an encrypted shellcode in a newly allocated memory in the heap and transfers execution to it.
Gelup has anti-dynamic analysis function. This is carried out by checking analysis/VM tools in the process, and if it’s running in a debugger, emulator, or sandbox.
TA505 packer makes use of GetLastError() call to avoid unpacking if it is running in an emulated environment.
It relies on a self-modifying unpacking technique, trying to acquire a block of writeable, executable memory, unpacking (decrypting and writing) code to the newly allocated memory and finally, transferring execution to the unpacked code in the newly allocated memory.
FlowerPippi collects some of the user’s information... id=<VICTIM_ID>&domain=<DOMAIN_NAME_OR_WORKGROUP>&proxy=<PROXY_SETTING>&rights=<IS_ADMIN>&os=<OS_VERSION_STR>&x64=<IS_X64>
Gelup has anti-dynamic analysis function. This is carried out by checking analysis/VM tools in the process, and if it’s running in a debugger, emulator, or sandbox.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final payload recovered from a TA505-packed sample.
A C++ downloader used by TA505 featuring anti-static and anti-dynamic analysis, runtime string/API decryption, UAC bypass via mocked trusted directories and DLL side-loading, persistence via scheduled tasks and shortcut files, and AES-encrypted JSON-over-HTTP C2 communications for downloading and executing additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.