PULSE NAME
APT36 sample analysis
WHITE PetrP.73 2025-12-21 Modified: 2026-01-20
50
IOCs
MEDIUM VOLUME
APT36 has been observed utilizing two distinct methods to execute malware on Linux and Windows platforms, focusing on the distribution of malicious files disguised as legitimate documents. On Linux, the attack begins with the creation of a `.local` directory with specific permissions (0755), followed by downloading three files from a target URL: `gkt3.1`, `http://gkt3.sh`, and `APPL FOR UPDATION.pdf`. The `http://gkt3.sh` script is executed after this download, which subsequently utilizes the `xdg-open` command to open the PDF file, potentially leading to further exploitation or malware execution. Conversely, on Windows platforms, APT36 employs a malicious shortcut (LNK file) named `APPL FOR UPDATION OF NAME BASED & OFFICIAL NIC E-MAIL ID.pdf.LNK`. This file initiates the execution of embedded code through the use of the `mshta.exe` tool, a legitimate Windows system application.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (17 / 50 total)
All domain CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1426bdff1ef4466c37631a51c2ba6e48 2025-12-21
FileHash-MD5 180c88e45db8a2bcc095f32ca71ab8f6 2025-12-21
FileHash-MD5 24e010830cbb42384bf609f8acf91c46 2025-12-21
FileHash-MD5 30fda797535a0f367ea2809426760020 2025-12-21
FileHash-MD5 403ea69b8b75e16a644d12053eb2659a 2025-12-21
FileHash-MD5 40ef50cc91a890ecb7726a72fe130424 2025-12-21
FileHash-MD5 57ba3d1bfc8724668c52b98908bf159a 2025-12-21
FileHash-MD5 5a9552f5d8bb031358cbacf827624186 2025-12-21
FileHash-MD5 689af44a940f293ea659603aee2323b3 2025-12-21
FileHash-MD5 75245a9be77dc6014e079cf249a98ab3 2025-12-21
FileHash-MD5 813b69e1ffeb70cdd5a63a8103a896d3 MD5 of 6cadcdb2c2cd1425a44fe08e00c4cfcff9498ee0 2025-12-21
FileHash-MD5 90796ed66e7f5f36b6317e6bdf9718ce 2025-12-21
FileHash-MD5 a4f1cc3537eb8dd669c3cc16cdf7b798 2025-12-21
FileHash-MD5 a53b1134f5bad31b407f5f597fd1cfa3 2025-12-21
FileHash-MD5 c345c4a04df2d324f594e2ae9040daf8 2025-12-21
FileHash-MD5 ceb715db684199958aa5e6c05dc5c7f0 2025-12-21
FileHash-MD5 de035f212161f33accc610793fdcaa67 MD5 of e0e89ee546fe04498aee0e1deb33e0b47ba8708a 2025-12-21