Elektrine lite

← Feed

@abuse_ch@ioc.exchange

Post #4044450

2026-07-23 06:14 UTC

Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users πŸ‡ΊπŸ‡¦πŸ•΅οΈ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4️⃣ Malware executes the PS command and obtains second stage from global-research .space/adv13.php global-research .space has been registered almost a year ago, which suggests that this campaign is already running since quite a while πŸ“… It also returns a fake HTTP 404, which indicates that the payload delivery is restricted to a handful targets 🎯 IOCs πŸ“‘ %ProgramData%\Microsoft\HTML Help\hhcolreg.dat %APPDATA%\Microsoft\HTML Help\hh.dat https://threatfox.abuse.ch/ioc/1855885/ https://threatfox.abuse.ch/ioc/1855883/ Malware sample πŸ“„ https://bazaar.abuse.ch/sample/32a962439ec0fb5559e494fe1ea6be039815d3c4c1cceb95b16dc123e5abde61/

Replies (2)

  • @netresec@infosec.exchange 2026-07-23 19:31

    @abuse_ch@ioc.exchange Here's another sample from December 2025 using the same technique. https://hybrid-analysis.com/sample/8b516c5c05ddbfbb2022976f049b73a8ad909f0db4a65a720fe5d9ce0bea9c95/693161ad4c5505cf7405d2da

    Open ##4044449

  • @resingm@infosec.exchange 2026-07-31 13:31

    @abuse_ch@ioc.exchange - Must be a former netops guy living by his favorite solution: "Just put it in the DNS"

    Open ##4279853