PULSE NAME
MintsLoader: StealC and BOINC Delivery
WHITE AlienVault 2025-01-20 Modified: 2025-02-19
67
IOCs
HIGH VOLUME
The eSentire Threat Response Unit identified a campaign involving MintsLoader, a PowerShell-based malware loader, delivering payloads like Stealc and BOINC client. MintsLoader uses a Domain Generation Algorithm and anti-VM techniques to evade detection. The infection process begins with a spam email link downloading a JScript file, which then executes PowerShell commands to retrieve and execute the malware stages. StealC, an information stealer, is delivered as the final payload, targeting sensitive data from browsers, applications, and crypto-wallets. The campaign affected organizations in the US and Europe, primarily in the Electricity, Oil & Gas, and Legal Services industries.
Indicators of Compromise (3 / 67 total)
All FileHash-SHA256 domain FileHash-MD5 FileHash-SHA1 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://62.204.41.177/edd20096ecef326d.php 2025-01-20
URL http://mubuzb3vvv.top/1.php?s=527 2025-01-20
URL https://t1jm05fdu6748emu5oon8nix1uk2ogyn.lovesnextmeeting.com/Uswl5JAnXI 2025-01-20