216.73.217.22

CoreWarrior Spreader Malware Surge

· Published 15/10/2024 11:26 · Modified 15/10/2024 11:45

Export JSON

Essential information

Published
15/10/2024 11:26
Modified
15/10/2024 11:45
Tags
2024-10-15 anti-analysis backdoor corewarrior evasion propagation trojan
Related entities
3 observables, 15 techniques (mitre), 1 malware

Description

This report delves into an analysis of , a persistent designed for rapid . It creates multiple copies of itself, attempts connections to various IP addresses, opens access, and hooks Windows UI elements for monitoring purposes. The malware employs techniques like anti-debugging, through randomized sleep timers, and virtual environment detection. It also references protocols like FTP, SMTP, and POP3 for potential data exfiltration. The report provides indicators of compromise, including hashes, and highlights SonicWall's proactive security measures to safeguard against this threat.

External references