Post #4044450
2026-07-23 06:14 UTC
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users πΊπ¦π΅οΈ
The malware sample:
1οΈβ£ Obtains the DNS A record of ns2.theendlessweb .com
2οΈβ£ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
3οΈβ£ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record
4οΈβ£ Malware executes the PS command and obtains second stage from global-research .space/adv13.php
global-research .space has been registered almost a year ago, which suggests that this campaign is already running since quite a while π
It also returns a fake HTTP 404, which indicates that the payload delivery is restricted to a handful targets π―
IOCs π‘
%ProgramData%\Microsoft\HTML Help\hhcolreg.dat
%APPDATA%\Microsoft\HTML Help\hh.dat
https://threatfox.abuse.ch/ioc/1855885/
https://threatfox.abuse.ch/ioc/1855883/
Malware sample π
https://bazaar.abuse.ch/sample/32a962439ec0fb5559e494fe1ea6be039815d3c4c1cceb95b16dc123e5abde61/
Replies (2)
-
@netresec@infosec.exchange 2026-07-23 19:31
@abuse_ch@ioc.exchange Here's another sample from December 2025 using the same technique. https://hybrid-analysis.com/sample/8b516c5c05ddbfbb2022976f049b73a8ad909f0db4a65a720fe5d9ce0bea9c95/693161ad4c5505cf7405d2da
-
@resingm@infosec.exchange 2026-07-31 13:31
@abuse_ch@ioc.exchange - Must be a former netops guy living by his favorite solution: "Just put it in the DNS"