MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Windows OdicLoader Linux Upload IconicLoader Tabla 1 BADCALL SimplexTea Figura
TYPEINDICATORDESCRIPTIONCREATED
YARA 35a04b3434dfe52464f32a831cd350cdb8c5b679 YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication. 2026-04-06
YARA 5b05170f0ffdcc3b740d25773d0de08869879b33 Emotet Payload 2026-04-06
URL https://www.welivesecurity.com/ 2026-04-06
URL https://github.com/eset/malware-ioc/ 2026-04-06
email github@eset.com 2026-04-06
email mathieu.tartare@eset.com 2026-04-06
hostname www.welivesecurity.com 2026-04-06
FileHash-MD5 a0f09634b9ec6b5418d9f6be9e3156ee 2026-04-06
FileHash-MD5 b091a3e0c109535655e1019b1c5dee63 2026-04-06
FileHash-MD5 b381724b956a3517f2dd17f716b00746 2026-04-06
FileHash-SHA1 a900f1d2690997bc0508446c70c71ae1e430b70e 2026-04-06
FileHash-SHA256 047762558e0fad2ca4d7f2ea925e83f483fa8cfdb7e1c26faf7dae81937d2cb1 2026-04-06
FileHash-SHA256 d68dad1c6f86786d0ef1401b46a989246014d61c5efa15b74b68029dc6c79b21 2026-04-06
FileHash-SHA256 0900f79b7c099f8ee4b6d68993bfefae815c8ea0605ef52c8689c07afca6cec1 2026-04-06
FileHash-SHA256 13a34a672e3d2c6bdef1ed0041ad831e54a7e4492203a0a9a5ba8a63c8c1a5d7 2026-04-06
FileHash-SHA256 1890663b64624ffde4323964aabcd0ab37848c0be5cd0596372f26875d4aa2fa 2026-04-06
FileHash-SHA256 201edec03748cfe4ae74c7ead490fe166a629ae5862cfea05dca997b9bc7f2f6 2026-04-06
FileHash-SHA256 39d48072f337731d0745d672ff153887efd661ab0c07e569d8abe8f4f5df5a71 2026-04-06
FileHash-SHA256 3af6fc92591776023b0c1e48aa6697b95f5d6c463d9533853b54905ec65b43c5 2026-04-06
FileHash-SHA256 65dcec457c99d635b8a4c4e650def86f6be42e145673295d83e3f7e659086a32 2026-04-06
FileHash-SHA256 7b0d3a159bb72fe418d2b5a1c4a8a72b267ad5441d1f63b22b000f8ac7542e54 2026-04-06
FileHash-SHA256 8101890a483c0b14fdbf34fa5a46101411746ca97437a844094175b80c455a90 2026-04-06
FileHash-SHA256 86f0d0901aceda457d9ba7b67196c6cd5508999c0e74de73f9e0cd142d345b68 2026-04-06
FileHash-SHA256 8a1b2abb317626ad6a17ccd8dc4b3eb033202c12542506bd8bf367cc83df0dde 2026-04-06
FileHash-SHA256 8aef3b313fb8c6cc94c6d170fd716e7e3e2eb7ab060b404fb8af5356c03adfa3 2026-04-06
FileHash-SHA256 8bc5012112af64230091bb4ce0e36c62c84c752627bac7a6f82be4f06d6ce2bd 2026-04-06
FileHash-SHA256 9d559734a2b77f91644c93b12767366de91aa8f642ae4a7dfb9a08f5760b8341 2026-04-06
FileHash-SHA256 a0493f6995be73d43195dedf6e786bb14ac88a363c942d365aef40a04ce4714c 2026-04-06
FileHash-SHA256 a67cbfaf8b883f44d1247c5a4855054ade5598d06194baca3917965c6360d824 2026-04-06
FileHash-SHA256 aff62e7b494823289ce2eee7d2837a1502a16fee6f961c3ae63a849633883d7f 2026-04-06
FileHash-SHA256 c3b9ff566cfdde588fb5b7da16353adcb4b9b058c030e171845d62b1a8ae8b85 2026-04-06
FileHash-SHA256 c77e8ecb839129bc8e17ce06cdda9cae35219a7e958261b47951dd71bd9a974d 2026-04-06
FileHash-SHA256 ea8ca60803c0daa33e401009ee7f942cab813a58f09f2f34557f89fe9ef51160 2026-04-06
domain getbumptop.com 2026-04-06
FileHash-MD5 00e5d052f9904e19653f2ec695cb2461 2026-04-06
FileHash-MD5 0b892f4428689112775a5daab8300267 2026-04-06
FileHash-MD5 1a0563f7fb85a678771450b131ed66fd 2026-04-06
FileHash-MD5 20f0110ed5e4e0d5384a496e4880139b 2026-04-06
FileHash-MD5 254f6d7f0b0757490df055cf78702540 2026-04-06
FileHash-MD5 25d76ee5fb5b890f2cc022d94a42fe19 2026-04-06
FileHash-MD5 276dba142e77c21d5730a29e19308108 2026-04-06
FileHash-MD5 2f04fbf92f04e5d23637486e552f0a74 2026-04-06
FileHash-MD5 33bce58bb0493deaf5f1492aa86c7e7f 2026-04-06
FileHash-MD5 3c428b1a3e5f57d887ec4b864fac5dcc 2026-04-06
FileHash-MD5 3cb8faccd5de434d415ab75c17e8fd86 2026-04-06
FileHash-MD5 43e2624ff4ca3403c9bada29611e481a 2026-04-06
FileHash-MD5 472612bc4a07dd94f8caf551cd6fba81 2026-04-06
FileHash-MD5 4e245004e7532249d9867075d680f38c 2026-04-06
FileHash-MD5 5080e561c4d04eefc12c4519128e1774 2026-04-06
FileHash-MD5 50811b0cb68f8d937ffe15fbb9c0ad60 2026-04-06
FileHash-MD5 52ac2155ece4452e24b5b2a307f6d3af 2026-04-06
FileHash-MD5 555e83ce7f5d280d7454af334571fb25 2026-04-06
FileHash-MD5 55a3f5085549323488d95851882e73f2 2026-04-06
FileHash-MD5 6082151bd56ea922e1357f5896a90d0a 2026-04-06
FileHash-MD5 68e03ed57ec741a4afbbcd11fab1bdbe 2026-04-06
FileHash-MD5 68ecc7bf207742829a688cf7ea3b25b8 2026-04-06
FileHash-MD5 6e1dc9ee4f553558025775d0142e36a8 2026-04-06
FileHash-MD5 6f20ba58551e13cfd87ec059327effd0 2026-04-06
FileHash-MD5 717b80f1abbd3db46c3672c7f04317cd 2026-04-06
FileHash-MD5 740b16cf8e8388c014b809780101546a 2026-04-06
FileHash-MD5 7576926b06f3f98440b509311001ccb1 2026-04-06
FileHash-MD5 7f335f341768626a767f969c787206a6 2026-04-06
FileHash-MD5 829eb78cf9d83a0ce391b5aeba2ce366 2026-04-06
FileHash-MD5 865402edfb399ade31acec7737ec0477 2026-04-06
FileHash-MD5 9b49291ea79f6e900632c6e0b001a89e 2026-04-06
FileHash-MD5 a783928ccd8cc48ce1b9f5c80eb0c4cf 2026-04-06
FileHash-MD5 a9af7475e858daaed9b440b133645061 2026-04-06
FileHash-MD5 afadff6da55a3f2ae48cb863e28437fa 2026-04-06
FileHash-MD5 b1c48e8e2b71efcf101bf50392e3e1db 2026-04-06
FileHash-MD5 b27eb566214c60b6a5feab1a4389fc83 2026-04-06
FileHash-MD5 b2a3034a02d7534a0ceea44ebeaa4090 2026-04-06
FileHash-MD5 b7d3c73026c6c451dd7e4b474f73f832 2026-04-06
FileHash-MD5 b9bb15ef6bb313e08dcb10d645b07b81 2026-04-06
FileHash-MD5 d7a950fefd60dbaa01df2d85fefb3862 2026-04-06
FileHash-MD5 e50ea7bd9d3e85c226131f0c7f869e46 2026-04-06
FileHash-MD5 e7ca76a3c9ee0564471671d500e3f0f3 2026-04-06
FileHash-MD5 eb80e47ad01200838930a7ab306e036d 2026-04-06
FileHash-MD5 f4fe1cb77e758e1ba56b8a8ec20417c5 2026-04-06
FileHash-MD5 f5e918805f952338e0c1c7adb56bd008 2026-04-06
FileHash-MD5 fabc417470d58f30fe31d480c212851d 2026-04-06
FileHash-SHA1 48ed68b0b070f3a9ba5b9a2878a7ad3b40809a60 SHA1 of 254f6d7f0b0757490df055cf78702540 2026-04-06
FileHash-SHA1 f21bf2f13f89d1c9dfd2844d57728102d5714eaa SHA1 of 6082151bd56ea922e1357f5896a90d0a 2026-04-06
FileHash-SHA256 6e3892b200f7e99814d4f8a7d1aab62cdd8f50c65d53f2c7f85bb41a73c991a0 SHA256 of 6082151bd56ea922e1357f5896a90d0a 2026-04-06
FileHash-SHA256 a8fa0b3e2d2aafba84c49a22b7f417818f6569eb33890b3926dec75b0850529a SHA256 of 254f6d7f0b0757490df055cf78702540 2026-04-06
FileHash-MD5 451c23709ecd5a8461ad060f6346930c MD5 of 58b0516d28bd7218b1908fb266b8fe7582e22a5f 2026-04-06
FileHash-MD5 6426fe4dc604c7f1784ed1d48ab4ffc8 MD5 of 3b88cda62cdd918b62ef5aa8c5a73a46f176d18b 2026-04-06
FileHash-MD5 760c35a80d758f032d02cf4db12d3e55 MD5 of 1c66e67a8531e3ff1c64ae57e6edfde7bef2352d 2026-04-06
FileHash-MD5 76111d9780b2d0b5adee61cf752d937e MD5 of 5b03294b72c0caa5fb20e7817002c600645eb475 2026-04-06
FileHash-MD5 9e4d9edb07c348b10863d89b6bb08141 MD5 of 65122e5129fc74d6b5ebafcc3376abae0145bc14 2026-04-06
FileHash-MD5 aac5a52b939f3fe792726a13ff7a1747 MD5 of f6760fb1f8b019af2304ea6410001b63a1809f1d 2026-04-06
FileHash-MD5 af2bc70f1c97a2f583f7b87aea3c8a6c MD5 of 7491bd61ed15298ce5ee5ffd01c8c82a2cdb40ec 2026-04-06
FileHash-MD5 c01dc42f65acaf1c917c0cc29ba63adc MD5 of d288766fa268bc2534f85fd06a5d52264e646c47 2026-04-06
FileHash-SHA1 0ca1723afe261cd85b05c9ef424fc50290dce7df 2026-04-06
FileHash-SHA1 1c66e67a8531e3ff1c64ae57e6edfde7bef2352d 2026-04-06
FileHash-SHA1 2acc6f1d4656978f4d503929b8c804530d7e7cf6 2026-04-06
FileHash-SHA1 3b88cda62cdd918b62ef5aa8c5a73a46f176d18b 2026-04-06
FileHash-SHA1 58b0516d28bd7218b1908fb266b8fe7582e22a5f 2026-04-06
FileHash-SHA1 5b03294b72c0caa5fb20e7817002c600645eb475 2026-04-06
FileHash-SHA1 65122e5129fc74d6b5ebafcc3376abae0145bc14 2026-04-06
FileHash-SHA1 7491bd61ed15298ce5ee5ffd01c8c82a2cdb40ec 2026-04-06
FileHash-SHA1 cad1120d91b812acafef7175f949dd1b09c6c21a 2026-04-06
FileHash-SHA1 d288766fa268bc2534f85fd06a5d52264e646c47 2026-04-06
FileHash-SHA1 dcef83d8ee080b54dc54759c59f955e73d67aa65 2026-04-06
FileHash-SHA1 f6760fb1f8b019af2304ea6410001b63a1809f1d 2026-04-06
FileHash-SHA256 4257bb11570ed15b8a15aa3fc051a580eab5d09c2f9d79e4b264b752c8e584fc SHA256 of d288766fa268bc2534f85fd06a5d52264e646c47 2026-04-06
FileHash-SHA256 5a07b09eea34d7faa9c37e2806a556cd95f97699597bd1123339849b6e942d95 SHA256 of 65122e5129fc74d6b5ebafcc3376abae0145bc14 2026-04-06
FileHash-SHA256 5e40d106977017b1ed235419b1e59ff090e1f43ac57da1bb5d80d66ae53b1df8 SHA256 of 58b0516d28bd7218b1908fb266b8fe7582e22a5f 2026-04-06
FileHash-SHA256 9352625b3e6a3c998e328e11ad43efb5602fe669aed9c9388af5f55fadfedc78 SHA256 of 5b03294b72c0caa5fb20e7817002c600645eb475 2026-04-06
FileHash-SHA256 aa4e398b3bd8645016d8090ffc77d15f926a8e69258642191deb4e68688ff973 SHA256 of 3b88cda62cdd918b62ef5aa8c5a73a46f176d18b 2026-04-06
FileHash-SHA256 cc307cfb401d1ae616445e78b610ab72e1c7fb49b298ea003dd26ea80372089a SHA256 of f6760fb1f8b019af2304ea6410001b63a1809f1d 2026-04-06
FileHash-SHA256 e2ecec43da974db02f624ecadc94baf1d21fd1a5c4990c15863bb9929f781a0a SHA256 of 1c66e67a8531e3ff1c64ae57e6edfde7bef2352d 2026-04-06
FileHash-SHA256 ea31e626368b923419e8966747ca33473e583376095c48e815916ff90382dda5 SHA256 of 7491bd61ed15298ce5ee5ffd01c8c82a2cdb40ec 2026-04-06
URL https://journalide.org/djour.php 2026-04-06
YARA 73ebb8715a33dce62f3ea8472ccbbdf4106f4be1 Rich Headers-based rule covering the IconicLoader and IconicStealer from the 3CX supply chain incident, and also payloads from the cryptocurrency campaigns from 2022-12 2026-04-06
domain apdl.cf 2026-04-06
domain journalide.org 2026-04-06
domain pe.rich 2026-04-06
domain od.lk 2026-04-06
hostname offer.pdf.zip 2026-04-06
email threatintel@eset.com 2026-04-06
domain fncbukvmnw.com 2026-04-06
domain glassdoornews.com 2026-04-06
domain lionshearts.buzz 2026-04-06
domain malisuguba.com 2026-04-06
domain mezlan.me 2026-04-06
domain plankproductions.com 2026-04-06
domain raniersec.com 2026-04-06
domain zevegan.com 2026-04-06
URL http://23.254.211.230:25 2026-04-06
URL http://23.254.211.230:443 2026-04-06
URL http://23.254.211.230:587 2026-04-06
URL http://23.254.211.230:80 2026-04-06
URL http://glassdoornews.com 2026-04-06
URL http://mezlan.me/ 2026-04-06
URL http://plankproductions.com/ 2026-04-06
URL http://zevegan.com/ 2026-04-06
URL https://23.254.211.230:443 2026-04-06
URL https://glassdoornews.com 2026-04-06
domain naveeocorp.xyz 2026-04-06
domain nxmnv.site 2026-04-06
FileHash-SHA256 216734e1ab6e337b500bde6871afcd08b6fbde755fcce69dd18689def204f86c 2026-04-06
FileHash-SHA256 34b4546e3468238702df24794e598add494beaeacf95df10af54d88b3d241e8a 2026-04-06
FileHash-SHA256 379e04008c61b63081aaa804823529ce7af1851e7532497b3f9274528b0f778a 2026-04-06
FileHash-SHA256 7b6ed450bba75fd243f84561acfa021421597ac735a1e3aadef00820b75aeaf4 2026-04-06
FileHash-SHA256 a858b53bf93d04e9a020044979a1a4a7fe03800c317656b536ee5b072e2b96ca 2026-04-06
FileHash-SHA256 c82d2405c24460a321660fad72e99c8774b21c27b1144f2866fb92eae24ff62d 2026-04-06
FileHash-SHA256 cd9a2af1a299cca858481c92bf9279edc54ddef1de0acf3baf4157790167ed92 2026-04-06
FileHash-SHA256 d0fca086459060de186520077bea5f3787896d4e74dd62d74c9a8cfc2f4a4317 2026-04-06
FileHash-SHA256 d18b6a18edb2e780ed1f8140985e1c5c1abc4b88c4f5f497905305ea2a0bdc33 2026-04-06
FileHash-SHA256 e00716e37a7198ae71a35cbfcdeb48fbe3e27b975aafae657bc951d135ce5431 2026-04-06
hostname www.misdatos.intes.com.mx 2026-04-06
YARA 35a04b3434dfe52464f32a831cd350cdb8c5b679 2026-04-06
URL https://labs.inquest.net/dfi/hash/f9b62b2aee5937e4d7f33f04f52ad5b05c4a1ccde6553e18909d2dc0cb595209 2026-04-06
FileHash-MD5 17b405710a0a1137e36601173e06ebdc MD5 of 510c5b598d83576f9b1da950b245a83927af7559 2026-04-06
FileHash-SHA1 510c5b598d83576f9b1da950b245a83927af7559 2026-04-06
FileHash-SHA256 f9b62b2aee5937e4d7f33f04f52ad5b05c4a1ccde6553e18909d2dc0cb595209 SHA256 of 510c5b598d83576f9b1da950b245a83927af7559 2026-04-06
CVE CVE-2024-40898 2026-04-06
FileHash-MD5 24bfe35b8c9c88c0a05d4c64d8d3ebae MD5 of ba3a789a8497be3970e4521c81cc4e8e9e02b44e 2026-04-06
FileHash-MD5 65ae65b110ace37606f55ab79a040bb3 2026-04-06
FileHash-MD5 7e470b98fc2378f4ed0e144bc765fae5 2026-04-06
FileHash-MD5 960a5c48e25cf2bca332e74e11d825c9 MD5 of da35c6816ace5daf4c6c1d57b93b09a82ecdc876 2026-04-06
FileHash-MD5 a5a4cee2eb89d2687c05ef74299f0dba 2026-04-06
FileHash-MD5 bf95d1fc1d10de18b32654b123ad5e1f 2026-04-06
FileHash-SHA1 b9bff5987be422887f2f402357b47db2288a1a42 2026-04-06
FileHash-SHA1 ba3a789a8497be3970e4521c81cc4e8e9e02b44e 2026-04-06
FileHash-SHA1 da35c6816ace5daf4c6c1d57b93b09a82ecdc876 2026-04-06
FileHash-SHA1 e4ee94211dbcbc65117b8010409db9b4aa93f67f 2026-04-06
FileHash-SHA256 343f3f18c5f99b3b36774aa6cb01bd6700f5baa89a11a924b6a4899be8107d75 2026-04-06
FileHash-SHA256 484f8e9f194ed9016274ef3672b2c52ed5f574fb71d3884edf3c222b758a75a2 SHA256 of da35c6816ace5daf4c6c1d57b93b09a82ecdc876 2026-04-06
FileHash-SHA256 553d33ea2d5f87552706721957ea643044ab181dff1a2e096787974a3b55911f 2026-04-06
FileHash-SHA256 cb82268b778703db75961cddef33a695a674f0dfd28b7e710b198ef2d26d3963 2026-04-06
FileHash-SHA256 d0c1e946f02503a290d24637b5c522145f58372a9ded9e647d24cd904552d235 SHA256 of ba3a789a8497be3970e4521c81cc4e8e9e02b44e 2026-04-06
SSLCertFingerprint 0c:c4:18:cf:96:e7:6e:ce:d6:97:3f:78:7a:67:1c:f9:84:ce:b2:66 2026-04-06
URL http://en.wikipedia.org/wiki/Windows_API 2026-04-06
URL https://github.com/eset/malware-ioc/ 2026-04-06
URL https://www.welivesecurity.com/ 2026-04-06
hostname en.wikipedia.org 2026-04-06
hostname www.welivesecurity.com 2026-04-06
FileHash-SHA256 0900f79b7c099f8ee4b6d68993bfefae815c8ea0605ef52c8689c07afca6cec1 2026-04-06
FileHash-SHA256 13a34a672e3d2c6bdef1ed0041ad831e54a7e4492203a0a9a5ba8a63c8c1a5d7 2026-04-06
FileHash-SHA256 1890663b64624ffde4323964aabcd0ab37848c0be5cd0596372f26875d4aa2fa 2026-04-06
FileHash-SHA256 201edec03748cfe4ae74c7ead490fe166a629ae5862cfea05dca997b9bc7f2f6 2026-04-06
FileHash-SHA256 39d48072f337731d0745d672ff153887efd661ab0c07e569d8abe8f4f5df5a71 2026-04-06
FileHash-SHA256 3af6fc92591776023b0c1e48aa6697b95f5d6c463d9533853b54905ec65b43c5 2026-04-06
FileHash-SHA256 65dcec457c99d635b8a4c4e650def86f6be42e145673295d83e3f7e659086a32 2026-04-06
FileHash-SHA256 7b0d3a159bb72fe418d2b5a1c4a8a72b267ad5441d1f63b22b000f8ac7542e54 2026-04-06
FileHash-SHA256 8101890a483c0b14fdbf34fa5a46101411746ca97437a844094175b80c455a90 2026-04-06
FileHash-SHA256 86f0d0901aceda457d9ba7b67196c6cd5508999c0e74de73f9e0cd142d345b68 2026-04-06
FileHash-SHA256 8a1b2abb317626ad6a17ccd8dc4b3eb033202c12542506bd8bf367cc83df0dde 2026-04-06
FileHash-SHA256 8aef3b313fb8c6cc94c6d170fd716e7e3e2eb7ab060b404fb8af5356c03adfa3 2026-04-06
FileHash-SHA256 8bc5012112af64230091bb4ce0e36c62c84c752627bac7a6f82be4f06d6ce2bd 2026-04-06
FileHash-SHA256 9d559734a2b77f91644c93b12767366de91aa8f642ae4a7dfb9a08f5760b8341 2026-04-06
FileHash-SHA256 a0493f6995be73d43195dedf6e786bb14ac88a363c942d365aef40a04ce4714c 2026-04-06
FileHash-SHA256 a67cbfaf8b883f44d1247c5a4855054ade5598d06194baca3917965c6360d824 2026-04-06
FileHash-SHA256 aff62e7b494823289ce2eee7d2837a1502a16fee6f961c3ae63a849633883d7f 2026-04-06
FileHash-SHA256 c3b9ff566cfdde588fb5b7da16353adcb4b9b058c030e171845d62b1a8ae8b85 2026-04-06
FileHash-SHA256 c77e8ecb839129bc8e17ce06cdda9cae35219a7e958261b47951dd71bd9a974d 2026-04-06
FileHash-SHA256 ea8ca60803c0daa33e401009ee7f942cab813a58f09f2f34557f89fe9ef51160 2026-04-06
References (1)
↗ http://dlvr.it/Sn3dHM