216.73.216.36

From Document to Script: Insides of Campaign

· Published 17/05/2024 09:38 · Modified 17/05/2024 10:03

Export JSON

Essential information

Published
17/05/2024 09:38
Modified
17/05/2024 10:03
Tags
2024-05-17 autoit campaign cybercrime darkgate java malicious obfuscation payload phishing
Related entities
11 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 malware

Description

This report examines a recent initiated via emails, seemingly from 'QuickBooks,' prompting users to install . Clicking the embedded link leads to downloading a JAR file. The JAR contains commands to fetch additional payloads, including an obfuscated script that establishes connections with remote servers, likely for purposes. The employs sophisticated techniques and historical URL patterns associated with threat actors.

External references