← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Hijacked: How Cybercriminals Are Turning Anti-Virus Software Against You
LevelBlue Labs has recently observed a malicious campaign abusing legitimate anti-virus products to remain undetected. Upon achieving execution, the threat actor deploys several executables to gain a foothold in the infected system. One of these executables caught our attention as it masqueraded as different anti-virus components, while in reality they offer a proxy service through a Command and Control (C&C) server. The binaries are based on the legitimate anti-virus components but are modified to include the malicious code. This activity seems to be a continuation of the activity already reported by Sophos in late April and marks a new iteration in the toolset of this threat actor. In this new iteration of the campaign, we have observed Malwarebytes, BitDefender and APEX products being targeted amongst others.
Indicators of Compromise (17)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | a57b8e9bea6144115796bfb723f3410c | MD5 of fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 | 2024-07-25 | |
| FileHash-MD5 | b6680e15c4f36e7b75fc6676bc911667 | MD5 of baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 | 2024-07-25 | |
| FileHash-MD5 | c73a9395d5eca18fd86700b086455c59 | MD5 of bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f | 2024-07-25 | |
| FileHash-SHA1 | 42896f8069c341a3e78f940dfcc4ebf4a5884471 | SHA1 of bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f | 2024-07-25 | |
| FileHash-SHA1 | ac47aa570a47e035fc72e15573521f5ad93433fa | SHA1 of baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 | 2024-07-25 | |
| FileHash-SHA1 | beb9ca52ff55b820848a19f2d700c71e946d59b5 | SHA1 of fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 | 2024-07-25 | |
| FileHash-SHA256 | 1ade6a15ebcbe8cb9bda1e232d7e4111b808fd4128e0d5db15bfafafc3ec7b8e | — | 2024-07-25 | |
| FileHash-SHA256 | 7d96ec8b72015515c4e0b5a1ae6c799801cf7b86861ade0298a372c7ced5fd93 | — | 2024-07-25 | |
| FileHash-SHA256 | 949faad2c2401eb854b9c32a6bb6e514ad075e5cbe96154c172f5f6628af43ed | — | 2024-07-25 | |
| FileHash-SHA256 | 9c1e0c8c5b9b9fe9d0aa533fb7d9d1b57db98fd70c4f66a26a3ed9e06ac132a7 | — | 2024-07-25 | |
| FileHash-SHA256 | 9dc809b2e5fbf38fa01530609ca7b608e2e61bd713145f84cf22c68809aec372 | — | 2024-07-25 | |
| FileHash-SHA256 | ab1f101f6cd7c0cffc65df720b92bc8272f82a1e13f207dff21caaff7675029f | — | 2024-07-25 | |
| FileHash-SHA256 | b92cf617a952f0dd2c011d30d8532d895c0cfbfd9556f7595f5b220e99d14d64 | — | 2024-07-25 | |
| FileHash-SHA256 | baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 | — | 2024-07-25 | |
| FileHash-SHA256 | bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f | — | 2024-07-25 | |
| FileHash-SHA256 | fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 | — | 2024-07-25 | |
| domain | halagifts.com | — | 2024-07-25 |