PULSE NAME
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion .
WHITE PetrP.73 2025-09-30 Modified: 2025-10-30
73
IOCs
HIGH VOLUME
In May 2024, an intrusion attributed to the Lunar Spider threat actor commenced when a user executed a malicious JavaScript file disguised as a tax form. This file, associated with the Lunar Spider group, contained obfuscated code that triggered the download of an MSI installer, which subsequently deployed a Brute Ratel DLL file using the Windows utility rundll32. Upon execution, the Brute Ratel loader injected Latrodectus malware into the explorer.exe process, establishing command and control (C2) communications with multiple domains. The attack began with extensive reconnaissance activities approximately one hour after the initial access, utilizing built-in Windows commands to enumerate hosts and domains. Subsequent actions included establishing a BackConnect session for remote access via VNC, and accessing an unattend.xml file to extract plaintext domain administrator credentials.
Indicators of Compromise (18 / 73 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://206.206.123.209:443 2025-09-30
URL http://45.129.199.214/vodeo/wg01ck01 2025-09-30
URL http://45.129.199.214/vodeo/wg01ck01. 2025-09-30
URL http://91.194.11.64/MSI.msi ead5ebf464c313176174ff0fdc3360a3477f6361d0947221d31287eeb04691b3 2025-09-30
URL http://94.232.249.186/vodeo/vid_wg01ck01 2025-09-30
URL http://94.232.249.186/vodeo/wg01ck01 2025-09-30
URL http://94.232.40.49/vodeo/wg01ck01 2025-09-30
URL http://filomeruginfor.com/christian/house/cwk01 2025-09-30
URL http://filomeruginfor.com/deolefor/wg01ck01m 2025-09-30
URL http://grasmertal.com/live/ 2025-09-30
URL http://resources.avtechupdate.com/samlss/vm.ico. 2025-09-30
URL http://techbulldigital.com/Apply/readme/VJICARU60DC?_WHBEXNIA=HNMIIIANEMPMLIDFEOPKLBDOEMPI 2025-09-30
URL http://techbulldigital.com/List/com2/9O29EO3IRSBB 2025-09-30
URL http://wehelpgood.xyz/Complete/v9.56/KT84GVGD135E 2025-09-30
URL http://wehelpgood.xyz/derive/n/nzoqjd9mme 2025-09-30
URL https://cloudmeri.com/comm.php 2025-09-30
URL https://illoskanawer.com/live/ 2025-09-30
URL https://workspacin.cloud/live/ 25fb23868ebf48348f9e438e00cb9b9d9b3a054f32482a781c762cc4f9cc6393 2025-09-30