PULSE NAME
WINELOADER Analysis
WHITE APT29 (Cozy Bear) AlienVault 2024-11-07 Modified: 2024-11-08
25
IOCs
MEDIUM VOLUME
APT29, also known as Cozy Bear, has targeted European diplomats using a sophisticated multi-stage attack chain involving a new modular backdoor called WINELOADER. The attack begins with a fake PDF invitation to a wine-tasting event, which leads to the download of a malicious HTA file. This file then downloads and executes the WINELOADER backdoor, which uses advanced evasion techniques such as DLL side-loading, encryption, and DLL hollowing. The malware communicates with command and control servers hosted on compromised websites, downloading additional modules and establishing persistence through scheduled tasks or registry keys. The campaign demonstrates APT29's focus on exploiting diplomatic relations between India and European nations, showcasing their advanced tactics and efforts to remain undetected.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
WINELOADER
Indicators of Compromise (25)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 30a762f747ba9432673b8b94066b270a 2024-11-07
FileHash-MD5 6e1b219fc0db106ff3a6e982fb7b9241 2024-11-07
FileHash-MD5 7961263963841010a049265956b14666 2024-11-07
FileHash-MD5 9e07a9b8dd3ae5e360cfacc20bd1ec38 2024-11-07
FileHash-SHA1 74dd1d535e675406d45d747a30ffd86e194039c7 2024-11-07
FileHash-SHA1 ba10a6e635ea2972ba49b97372882287e555977f 2024-11-07
FileHash-SHA1 dd66cdc4242e8561ddacbcd1de95011fef927963 2024-11-07
FileHash-SHA1 f6aad0fbffc4f3bbcdcdbd1deee11b298ef86039 2024-11-07
FileHash-SHA256 1c7593078f69f642b3442dc558cddff4347334ed7c96cd096367afd08dca67bc 2024-11-07
FileHash-SHA256 3739b2eae11c8367b576869b68d502b97676fb68d18cc0045f661fbe354afcb9 2024-11-07
FileHash-SHA256 72b92683052e0c813890caf7b4f8bfd331a8b2afc324dd545d46138f677178c4 2024-11-07
FileHash-SHA256 7600d4bb4e159b38408cb4f3a4fa19a5526eec0051c8c508ef1045f75b0f6083 2024-11-07
FileHash-SHA256 ad43bbb21e2524a71bad5312a7b74af223090a8375f586d65ff239410bbd81a7 2024-11-07
FileHash-SHA256 b014cdff3ac877bdd329ca0c02bdd604817e7af36ad82f912132c50355af0920 2024-11-07
FileHash-SHA256 c1223aa67a72e6c4a9a61bf3733b68bfbe08add41b73ad133a7c640ba265a19e 2024-11-07
FileHash-SHA256 e477f52a5f67830d81cf417434991fe088bfec21984514a5ee22c1bcffe1f2bc 2024-11-07
FileHash-SHA256 f61cee951b7024fca048175ca0606bfd550437f5ba2824c50d10bef8fb54ca45 2024-11-07
URL http://seeceafcleaners.co.uk/cert.php 2024-11-07
URL https://castechtools.com/api.php 2024-11-07
URL https://passatempobasico.com.br/wine.php 2024-11-07
URL https://seeceafcleaners.co.uk/cert.php 2024-11-07
URL https://seeceafcleaners.co.uk/wine.php 2024-11-07
domain castechtools.com 2024-11-07
domain passatempobasico.com.br 2024-11-07
domain seeceafcleaners.co.uk 2024-11-07