PULSE NAME
Wineloader - Analysis of the Infection Chain
WHITE APT29 AlienVault 2024-06-06 Modified: 2024-06-06
15
IOCs
MEDIUM VOLUME
The analysis examines the Wineloader backdoor, a modular malware attributed to the APT29 threat group, which allows further tools or modules to be downloaded through an encrypted command and control channel. It starts with a phishing email luring targets with a wine tasting event invitation. Executing the obfuscated HTA file downloads the Wineloader payload, which utilizes sideloading and creates scheduled tasks or registry entries for persistence. Techniques to deobfuscate the JavaScript code are provided to extract valuable intelligence from obfuscated payloads.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Wineloader
Indicators of Compromise (15)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 30a762f747ba9432673b8b94066b270a 2024-06-06
FileHash-MD5 6e1b219fc0db106ff3a6e982fb7b9241 2024-06-06
FileHash-MD5 7961263963841010a049265956b14666 2024-06-06
FileHash-SHA1 ba10a6e635ea2972ba49b97372882287e555977f 2024-06-06
FileHash-SHA1 dd66cdc4242e8561ddacbcd1de95011fef927963 2024-06-06
FileHash-SHA1 f6aad0fbffc4f3bbcdcdbd1deee11b298ef86039 2024-06-06
FileHash-SHA256 1c7593078f69f642b3442dc558cddff4347334ed7c96cd096367afd08dca67bc 2024-06-06
FileHash-SHA256 3739b2eae11c8367b576869b68d502b97676fb68d18cc0045f661fbe354afcb9 2024-06-06
FileHash-SHA256 72b92683052e0c813890caf7b4f8bfd331a8b2afc324dd545d46138f677178c4 2024-06-06
FileHash-SHA256 7600d4bb4e159b38408cb4f3a4fa19a5526eec0051c8c508ef1045f75b0f6083 2024-06-06
FileHash-SHA256 ad43bbb21e2524a71bad5312a7b74af223090a8375f586d65ff239410bbd81a7 2024-06-06
FileHash-SHA256 b014cdff3ac877bdd329ca0c02bdd604817e7af36ad82f912132c50355af0920 2024-06-06
FileHash-SHA256 c1223aa67a72e6c4a9a61bf3733b68bfbe08add41b73ad133a7c640ba265a19e 2024-06-06
FileHash-SHA256 e477f52a5f67830d81cf417434991fe088bfec21984514a5ee22c1bcffe1f2bc 2024-06-06
FileHash-SHA256 f61cee951b7024fca048175ca0606bfd550437f5ba2824c50d10bef8fb54ca45 2024-06-06