PULSE NAME
MINT STEALER: Running by a BulletProof Hoster
WHITE Artem AlienVault 2024-08-16 Modified: 2024-09-15
30
IOCs
MEDIUM VOLUME
This article provides an analysis of the Mint Stealer, a Python-based information stealer capable of harvesting sensitive data from infected machines. It delves into the stealer's functionality, history, and the infrastructure behind its operations, including its link to a bulletproof hosting service called Cash Hosting run by a threat actor known as 'Artem.' The analysis covers the offensive services offered by Artem, such as Cash RAT, Cash Ransomware, and Amail Hosting, as well as the malware's code analysis, attack vectors, and indicators of compromise (IOCs).
Indicators of Compromise (12 / 30 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 33559005506dae5967c8ddeaa8a65f5b 2024-08-16
FileHash-MD5 3832f42b8a1655a1ff2cce00aec7435b 2024-08-16
FileHash-MD5 4629bd8e5e8cfe7256d1505e444c7db8 2024-08-16
FileHash-MD5 69cc2e20ea7a51666b8c14be90441073 2024-08-16
FileHash-MD5 7dda8c4e9ac5fe4603e4674c31f9c8bb 2024-08-16
FileHash-MD5 9f037593071344bc1354e5a619f914f4 2024-08-16
FileHash-MD5 a1671d1d339b188fa3f437e79ccf21d1 2024-08-16
FileHash-MD5 a3d27166eb3a33cc84294c54ade0490d 2024-08-16
FileHash-MD5 ac449f08bd7edcecabfbf7c1231c02e8 2024-08-16
FileHash-MD5 afefdbd2bf7a6a622eaf09ab4a1adb3b 2024-08-16
FileHash-MD5 c66ee818a2295aac69baa17df301de34 2024-08-16
FileHash-MD5 e6e620e5cac01f73d0243dc9cf684193 2024-08-16