PULSE NAME
Hijacked: How Cybercriminals Are Turning Anti-Virus Software Against You
WHITE AlienVault 2024-07-25 Modified: 2024-08-24
17
IOCs
MEDIUM VOLUME
LevelBlue Labs has recently observed a malicious campaign abusing legitimate anti-virus products to remain undetected. Upon achieving execution, the threat actor deploys several executables to gain a foothold in the infected system. One of these executables caught our attention as it masqueraded as different anti-virus components, while in reality they offer a proxy service through a Command and Control (C&C) server. The binaries are based on the legitimate anti-virus components but are modified to include the malicious code. This activity seems to be a continuation of the activity already reported by Sophos in late April and marks a new iteration in the toolset of this threat actor. In this new iteration of the campaign, we have observed Malwarebytes, BitDefender and APEX products being targeted amongst others.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SbaProxy
Indicators of Compromise (17)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a57b8e9bea6144115796bfb723f3410c MD5 of fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 2024-07-25
FileHash-MD5 b6680e15c4f36e7b75fc6676bc911667 MD5 of baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 2024-07-25
FileHash-MD5 c73a9395d5eca18fd86700b086455c59 MD5 of bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f 2024-07-25
FileHash-SHA1 42896f8069c341a3e78f940dfcc4ebf4a5884471 SHA1 of bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f 2024-07-25
FileHash-SHA1 ac47aa570a47e035fc72e15573521f5ad93433fa SHA1 of baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 2024-07-25
FileHash-SHA1 beb9ca52ff55b820848a19f2d700c71e946d59b5 SHA1 of fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 2024-07-25
FileHash-SHA256 1ade6a15ebcbe8cb9bda1e232d7e4111b808fd4128e0d5db15bfafafc3ec7b8e 2024-07-25
FileHash-SHA256 7d96ec8b72015515c4e0b5a1ae6c799801cf7b86861ade0298a372c7ced5fd93 2024-07-25
FileHash-SHA256 949faad2c2401eb854b9c32a6bb6e514ad075e5cbe96154c172f5f6628af43ed 2024-07-25
FileHash-SHA256 9c1e0c8c5b9b9fe9d0aa533fb7d9d1b57db98fd70c4f66a26a3ed9e06ac132a7 2024-07-25
FileHash-SHA256 9dc809b2e5fbf38fa01530609ca7b608e2e61bd713145f84cf22c68809aec372 2024-07-25
FileHash-SHA256 ab1f101f6cd7c0cffc65df720b92bc8272f82a1e13f207dff21caaff7675029f 2024-07-25
FileHash-SHA256 b92cf617a952f0dd2c011d30d8532d895c0cfbfd9556f7595f5b220e99d14d64 2024-07-25
FileHash-SHA256 baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 2024-07-25
FileHash-SHA256 bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f 2024-07-25
FileHash-SHA256 fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 2024-07-25
domain halagifts.com 2024-07-25