2026-07-22 14:32 UTC
๐ฏ IOCs and behavioral patterns:
Python RAT (Stage 1):
C2: live.rnsn[.]live โ 69.169.111[.]81, TCP 8585
HTTP request markers: GET /International, X-Secret: 12345, Host: www.porsche[.]com, Referer: /|1.1.3
HTTP response decoy markers: Fullscreen Spinner + commands encoded in comment strings
OVERLORD RAT (Stage 2):
C2: lord.kirkdridebridge[.]com โ 163.245.218[.]93, TCP 5173, mTLSv1.3 channel encryption
Host artifacts:
C:\Users\Public\Windows\win32\we.exe
โฆ\run.vbs
โฆ\win6\exo.exe
.cmd
C:\ProgramData\sysid.txt (we.exe bot UUID)
C:\ProgramData\DeepSkyBlueIndianRed\* โ FnHotkeyUtility.exe, spkvol.dll, ludp.dll, msvcp140.dll, vcruntime140*.dll dropped executables
Registry:
HKCU...\Run: SkypeUpd=โฆ\win32\we.exe
HKCU...\Run: Winrarservice=โฆ\win32\run.vbs
Mutexes:
Global\Overlord-1_oVC9y33fSmT7DVUv0HJn9Y (ForestGreenLightSlateGray object)
Inno Setup cmdline password: f1846950-ca2f-4f9b-bd08-4807e431faa9
SHA256:
38cec7299bcbcc334633c87de5ed0d8355df8c73fadd26a8b5ca3862c2ea4357 (we.exe)
6805a1cb9b26b629f94aa3cf062e78eb4a5d259f459c0d8ca5a43cc08b16154b (client1.1.3.pyc)
7f53b7a21ba1418f56afac2f5f9db18bcca48d0c9ab7c3bee15a01db57d5fe5c (exo.exe)
9ab2f85ab539cea0f868c0b2a5219c3a8ccfef5365d74cc2cd455cb06d243f65 (upd.exe)
31c97b6e93112cae7bfce17d5979ccd513111b74165fc6ef471a9f8c821ae879 (spkvol.dll)
๐ MITRE ATT&CK:
T1059 โ Command and Scripting Interpreter
T1105 โ Ingress Tool Transfer
T1547.001 โ Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
T1027 โ Obfuscated Files or Information
T1574.002 โ Hijack Execution Flow: DLL Side-Loading
T1113 โ Screen Capture
T1123 โ Audio Capture
T1056.001 โ Input Capture: Keylogging
T1041 โ Exfiltration Over C2 Channel
Replies (0)
No replies.