PULSE NAME
DuneQuixote campaign targets Middle Eastern entities with malware
WHITE AlienVault 2024-04-19 Modified: 2024-04-19
55
IOCs
HIGH VOLUME
In this analysis, we uncover a malicious campaign dubbed 'DuneQuixote' that employs droppers disguised as the legitimate Total Commander installer to deliver a backdoor implant called 'CR4T'. This implant, available in both C/C++ and Golang versions, grants attackers access to compromised systems, enabling command execution, file management, and persistence through scheduled tasks. The campaign exhibits advanced evasion techniques, including anti-analysis checks, memory-only payloads, and unique infrastructure designed for stealth. The primary targets appear to be government entities in the Middle East region.
Indicators of Compromise (55)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 00130e1e7d628c8b5e2f9904ca959cd7 2024-04-19
FileHash-MD5 0d740972c3dff09c13a5193d19423da1 2024-04-19
FileHash-MD5 0fdbe82d2c8d52ac912d698bb8b25abc 2024-04-19
FileHash-MD5 135abd6f35721298cc656a29492be255 2024-04-19
FileHash-MD5 1bba771b9a32f0aada6eaee64643673a 2024-04-19
FileHash-MD5 258b7f20db8b927087d74a9d6214919b 2024-04-19
FileHash-MD5 3aaf7f7f0a42a1cf0a0f6c61511978d7 2024-04-19
FileHash-MD5 3cc77c18b4d1629b7658afbf4175222c 2024-04-19
FileHash-MD5 4324cb72875d8a62a210690221cdc3f9 2024-04-19
FileHash-MD5 450e589680e812ffb732f7e889676385 2024-04-19
FileHash-MD5 48c8e8cc189eef04a55ecb021f9e6111 2024-04-19
FileHash-MD5 4f29f977e786b2f7f483b47840b9c19d 2024-04-19
FileHash-MD5 5200fa68b6d40bb60d4f097b895516f0 2024-04-19
FileHash-MD5 56d5589e0d6413575381b1f3c96aa245 2024-04-19
FileHash-MD5 5759acc816274d38407038c091e56a5c 2024-04-19
FileHash-MD5 5a04d9067b8cb6bcb916b59dcf53bed3 2024-04-19
FileHash-MD5 5e85dc7c6969ce2270a06184a8c8e1da 2024-04-19
FileHash-MD5 606fdee74ad70f76618007d299adb0a4 2024-04-19
FileHash-MD5 6cfec4bdcbcf7f99535ee61a0ebae5dc 2024-04-19
FileHash-MD5 71a8b4b8d9861bf9ac6bd4b0a60c3366 2024-04-19
FileHash-MD5 72c4d9bc1b59da634949c555b2a594b1 2024-04-19
FileHash-MD5 7b9e85afa89670f46f884bb3bce262b0 2024-04-19
FileHash-MD5 828335d067b27444198365fac30aa6be 2024-04-19
FileHash-MD5 84ae9222c86290bf585851191007ba23 2024-04-19
FileHash-MD5 91472c23ef5e8b0f8dda5fa9ae9afa94 2024-04-19
FileHash-MD5 996c4f78a13a8831742e86c052f19c20 2024-04-19
FileHash-MD5 9b991229fe1f5d8ec6543b1e5ae9beb4 2024-04-19
FileHash-MD5 9d20cc7a02121b515fd8f16b576624ef 2024-04-19
FileHash-MD5 a0802a787537de1811a81d9182be9e7c 2024-04-19
FileHash-MD5 a4011d2e4d3d9f9fe210448dd19c9d9a 2024-04-19
FileHash-MD5 abf16e31deb669017e10e2cb8cc144c8 2024-04-19
FileHash-MD5 b0e19a9fd168af2f7f6cf997992b1809 2024-04-19
FileHash-MD5 c70763510953149fb33d06bef160821c 2024-04-19
FileHash-MD5 cc05c7bef5cff67bc74fda2fc96ddf7b 2024-04-19
FileHash-MD5 cf4bef8537c6397ba07de7629735eb4e 2024-04-19
FileHash-MD5 db786b773cd75483a122b72fdc392af6 2024-04-19
FileHash-MD5 f151be4e882352ec42a336ca6bff7e3d 2024-04-19
FileHash-MD5 f1b6aa55ba3bb645d3fde78abda984f3 2024-04-19
FileHash-MD5 f3988b8aaaa8c6a9ec407cf5854b0e3b 2024-04-19
FileHash-MD5 fb2b916e44abddd943015787f6a8dc35 2024-04-19
FileHash-SHA1 0e6072efb087ef19318a03a0509758fe9543222a 2024-04-19
FileHash-SHA1 17ffa01187ce7eef1a2e9a989d21e7b744714064 2024-04-19
FileHash-SHA1 2b69929e1bda591e8178134e92f3e4df5dd13330 2024-04-19
FileHash-SHA256 17119d30e632434e04d2106cf3d0b361d5c69180550e3db8ef07aa76c5e586dc 2024-04-19
FileHash-SHA256 446c20567ef09819ad160537f49efe9f242d8eacde86eb662571c0be56f0a00d 2024-04-19
FileHash-SHA256 8dade177642a50ff101519b159d38a41aedf157df44f0a875310f7f21c2e9808 2024-04-19
domain commonline.space 2024-04-19
domain userfeedsync.com 2024-04-19
hostname e1awq1lp.commonline.space 2024-04-19
hostname g1sea23g.commonline.space 2024-04-19
hostname mc.commonline.space 2024-04-19
hostname service.userfeedsync.com 2024-04-19
hostname telemetry.commonline.space 2024-04-19
hostname telemetry.userfeedsync.com 2024-04-19
hostname tg1sea23g.commonline.space 2024-04-19