Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
it does contain a few other interesting techniques that ‘get the job done’, like the mechanism for spreading via USB drives
sending personalized SMS messages to their potential victims to lure them to landing pages hosting the malware, disguised as postal tracking sites
the website truecryptrussia.ru has been serving modified versions of the encryption software that included a backdoor to selected targets. Clean versions of the application are served to normal visitors
The Potao trojan-droppers arrived (commonly via phishing emails) at victims’ systems in the form of executables with the icon of a Microsoft Word document, to trick the users into opening them and thereby running the malware.
This algorithm is also often used for hashing function names... if you look at the source code of the Conti ransomware leak, you can see Murmurhash2A function... hashing Win32API functions via MurmurHash2A.
static LPVOID getAPIAddr(HMODULE h, unsigned int myHash) { ... if (MurmurHash2A(pFuncName, strlen(pFuncName), 0) == myHash) { ... return (LPVOID)((LPBYTE)h + fAddr[fOrd[i]]); } }
The communication uses strong cryptography in two stages. The first stage is the key exchange and the second stage is the actual exchange of data.
The DLL is dropped to the following path, loaded and injected into explorer.exe... this instance will try to inject itself into the address space of several running legitimate and Internet-facing processes
Poker2.dll... Disables spreading through USB drives, deletes specific Registry keys, and kills processes belonging to the malware.
GetAllSystemInfo.dll... Collects various kinds of system information, including: system identifying information, proxy and language settings, lists of processes, installed software, recently opened files, and so on.
Enumerates all drives and creates a list of potentially interesting files: images and documents.
131 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family mentioned as using the MurmurHash2 hashing technique in the wild.
A modular cyber-espionage malware family used in targeted and some mass-spread campaigns. It is delivered via phishing-style droppers masquerading as documents, fake postal-service websites, spear-phishing SMS, USB propagation, and in some cases via trojanized TrueCrypt software. It installs a DLL, persists via the Run registry key, injects into explorer.exe and internet-facing processes, communicates with C2 using RSA-2048 and AES-256, and downloads plugins for keylogging, password theft, screenshots, file theft, browser history collection, and system reconnaissance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.