PULSE NAME
Fake Advanced IP Scanner Installer Delivers Dangerous Backdoor
WHITE AlienVault 2024-06-06 Modified: 2024-06-06
15
IOCs
MEDIUM VOLUME
Security researchers discovered a malicious version of the Advanced IP Scanner installer, which contained a backdoored DLL module. The compromised installer was distributed through a typo-squatted domain and appeared in search results for the legitimate software. When executed, the installer injected a CobaltStrike beacon, a powerful remote access tool often used by threat actors, into a newly created process. This allowed the attackers to maintain control over the compromised system and potentially move laterally within the network.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
CobaltStrike
Indicators of Compromise (2 / 15 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 21cdd0a64e8ac9ed58de9b88986c8983 2024-06-06
FileHash-MD5 723227f3a71001fb9c0cd28ff52b2636 2024-06-06