PULSE NAME
Glupteba: Hidden Malware Delivery in Plain Sight
WHITE AlienVault 2020-06-24 Modified: 2020-06-24
58
IOCs
HIGH VOLUME
This morning, SophosLabs is publishing a report on a malware family whose infection numbers have been steadily growing since the beginning of the year. This malware, with its hard-to-pronounce name, has been getting regular updates and feature enhancements that seem to be focused on its ability to conceal itself from detection on infected computers. In our report, we’ve taken a deep dive into what makes the Glupteba malware distinctive. The core malware is, in essence, a dropper with extensive backdoor functionality, but it is a dropper that goes to great efforts to keep itself, and its various components, hidden from view by the human operator of an infected computer, or the security software charged with its protection.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Glupteba Trojan:Win32/Glupteba VirTool:Win64/Glupteba
Indicators of Compromise (7 / 58 total)
All domain FileHash-SHA256 URL hostname BitcoinAddress FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 89c47e27bec5a374476ffaf92ab2b6d2 MD5 of 407c70f0c1a1e34503dae74dd973cf037d607e3c4deb8f063d33f2142f1baf71 2020-06-24
FileHash-MD5 705e482bbc7e2352ea1d3752a1717bb3 MD5 of 6b0d90a0571ec870fa26372a1c5d83d06e8febca130a8f710e0c389a3054e05c 2020-06-24
FileHash-MD5 10260f22b1d86f816a9680e0f620cf7c MD5 of eb35bb221de38f5953f923cd349b4c85a50145329152a8aaa01e4cd8602a560e 2020-06-24
FileHash-MD5 24e0013035473ba9d9af84f606340d51 MD5 of 04d71e8af8b5cbec912b82b6ebef7c19c5b888873dfd4609b1e38b2a6c398b2e 2020-06-24
FileHash-MD5 9155e8dbc4ee97b39f9977f4100a39b6 MD5 of dec11036bca8384f81c0c1d534e1f37fd2864c974dad020f32b835af3c7c4e28 2020-06-24
FileHash-MD5 e5c9a456e3646af493e694d7640a93b6 MD5 of 20e983e90144c385996eeb2edb584d654d898c34725e149682170f870ee12870 2020-06-24
FileHash-MD5 6130078138001184cb492a1472b677f5 MD5 of 8d19c59db26a3e0a3251c5f05e143558bf009ed0b46fb9b6151f98441407ae8b 2020-06-24