The Pumpkin Eclipse - Chalubo Malware
· Published 04/06/2024 15:58 · Modified 04/06/2024 16:31
Essential information
- Published
- 04/06/2024 15:58
- Modified
- 04/06/2024 16:31
- Tags
- 2024-06-04 actiontec black body button chalubo chalubo malware close code contact copy ddos download enterprise find footer form header dropdown iconbutton link lotus labs lua script lumen main meta next november october open path product reload script soho solutions span star template write
- Related entities
- 176 observables, 10 techniques (mitre), 1 malware
Description
Chalubo is a commodity remote access trojan (RAT). First identified in 2018, employed savvy tradecraft to obfuscate its activity; it removed all files from disk to run in-memory, assumed a random process name already present on the device, and encrypted all communications with the command and control (C2) server. Chalubo has payloads designed for all major SOHO/IoT kernels, pre-built functionality to perform DDoS attacks, and can execute any Lua script sent to the bot.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (176)
91.211.88.22545.116.160.6245.116.160.18245.116.160.15445.116.160.11545.116.160.10545.116.160.10038.54.27.204216.118.241.206216.118.241.205216.118.241.204216.118.241.203216.118.241.2022.59.223.2532.59.223.2262.59.223.2182.59.223.2132.59.223.1442.59.222.992.59.222.972.59.222.352.59.222.1462.59.222.1262.59.222.1252.59.222.1242.59.222.102194.36.190.99185.189.241.246185.189.241.180185.189.240.21180.178.46.245180.178.46.244180.178.46.242141.193.159.11141.193.159.10139.5.202.19139.5.202.18116.213.39.6116.213.39.5116.213.39.4116.213.39.3116.213.39.2114.29.255.77114.29.255.123112.121.165.78112.121.165.76112.121.165.75107.148.88.123107.148.0.182104.233.210.119104.233.210.118104.233.167.82104.233.167.81104.233.167.63104.233.167.62104.233.167.103104.233.166.194104.233.166.129103.84.84.251103.248.22.5103.248.22.16103.244.2.217103.244.2.171103.244.2.170103.140.187.149103.117.147.67103.117.146.222103.117.146.220103.117.146.219103.117.146.218103.117.145.110103.117.145.109103.117.145.108103.117.145.107103.117.145.10691.211.88.634.19.73.92.59.222.3185.189.240.13180.178.46.246180.178.46.243139.5.202.106112.121.165.77112.121.165.74103.117.147.66103.84.84.250103.244.2.21836.75.75.75138.112.25.25123.181.24.361.13.16.4571.162.181.51http://104.233.210.119:51248/get_scrpchttp://104.233.210.119:51248/get_fwuueicj.www.v5002.cnhttps://www.v5002.cnhttps://mh.55dmh.comhttps://m.isanyin.comhttps://m.aiguoba.comhttps://dh.id3cqcmgjcb.tophttps://cu6s.comhttp://xmsecu100.net/23652xxxxx000008skcai/res.dathttp://xmsecu.net/00030695mcksiqq/res.dat\thttp://xmsecu.net/00030695mcksiqq/res.dathttp://xmsecu.io/c638020vkklkjjiu/res.dathttp://xmsecu.io/00030678bbgstrjs/res.dathttp://xmsecu.io/00030674uucyttsikk/res.dathttp://secu100.com/23652xxxxx000008skcai/res.dathttp://sainnguatc.com:8080/ASUHALUMNABTC/res.dathttp://sainnguatc.com:8080/ASUHALUMNABTChttp://coreconf.net:8080/E2XRIEGSOAPU3Z5Q8/mipshttp://nihiosuxnmo.com:8080/SASBCKXOWYALLCZXFhttp://coreconf.net:8080/E2XRIEGSOAPU3Z5Q8http://ammhdfgygb.com/dldsc522dsdasd/res.dathttp://91.211.88.6:8080/ASUHALUMNABTChttp://91.211.88.225:8080/SASBCKXOWYALLCZXFhttp://2.59.222.97/dldsc522dsdasd/res.dathttp://194.36.190.99:38291/as/crtarm3http://185.189.240.13:8080/E2XRIEGSOAPU3Z5Q8/res.dathttp://185.189.240.13:8080/E2XRIEGSOAPU3Z5Q8mh.55dmh.comm.isanyin.comm.aiguoba.comlighten.medyamol.comdh.id3cqcmgjcb.topaxon-stall.riddlecamera.netxmsecu100.netxmsecu.netxmsecu.iosecu100.comsainnguatc.comnihiosuxnmo.comcu6s.comcoreconf.netammhdfgygb.com2fgithub.comf9db9632ffd7e3bd5b700025fa9278420de0778029fe2eedb6ea7b3d7b999ef6f5894f0cc7d9da2f188b740bb0596206038d9dba430c7d2a145d7454d9f1b4dbf37eaf27fe12b105c6661d303537787959eeb4bf52c6937d9165fd6b569faf30ed9511c16229f4bb41f461e90fff7964e79f2c2d27e7de2b107e4d003e9e0defe5030083c101058f52394820420a372bf93bcac2d802902d4d4c91470c96b608d9322af52b941e76bec3d2596a1c1be47dffc4fb161656da2c7c45b3d492cfd8d68f2ed30f344122db9f9e2729787450e1e8653e98bd61026fb4d75bf89de664d6778d5ad096516b881bbf2aca2d790b5217dfb83bb256e3f9d710056c9b512ac5317722effa07b56f9e81ef096b1711048eac6629c0ec72d8e8c72c6aae8f41d0643c777b0b24ca747f7dc79d3bdfbc04d3095ded760e6a54fa62bfa6945df3bdef8e089ffa00794f40f14ad3cdb8f1629241a4ac313bef8fe3d38e08207e4cb5fc0c265eb192b2a2d778e66d6f076e876eeacf57c3927e406b4e1b72152038b2e2193e49ee1240be30f5040dbb5e2c973cdfb02c3ea88ef4ffeda884de28c2a9cea205140babed24faea1b27f62b2f36464b8562223d96ecb617258a2fd2849b929bcc182c39540767a9b8237a8436c82997c68d4d2ba710241387c39c27f5967289406b0da030a93cefaa2644b109260565f5f767b95ce2a5d96d49c57bf28f4b61975539dbfe903f448636a48168351018801f2581a63d97179c37cad9798639bbb3ffe5fa51334c6ab4d45ae1647a29a97f061a9456991333ab166b52fd847e7f8209803d786660c5ba6d19ce59f76fe26e3e33e50cbe6dd663d40ad5697a81bbb1f7055cd3f30db8bb2a104b969914ccd520cf85c24b25ba5b0c7202067a6cdae75006d44d9b61093e5e65ae45c0d153bcc87c6a69974cbdfd6fc3b58b6be5b4bc461f1ba931bfe773df66bf5f8052626adbdf2b1156a06d0da2d8d3d1619564061e62a6352f0ce1a06d2883d46eb69df16322b30e8a2a9c65e2d32f5f5fc8534d490312823a49e2a13afc8a7b6b026280c79db704465fddd8a1fdc3765b9405418b654c9418e514ae3420c72af58d418adefca43644bf2bf14d89cc5a5b7874b18e8365e07624946a33518988aea4c72478a285a36047b4ba554a757659437e986acd685ad3ce48bf010efff22aa866c0fa066b0e64e510ecb026dd1a5621cdb8d07900a333d022a9696c1a6f7e45d6cfc713558c462a3ace7c4b426f51c421f69ad5d7a8de69efa798d1784ce7b41886dece435b879a5815a7f7a2c249c04e56dfb17ac16acddfcf9eff7ae82d70294a8ec70b6365ab43a07441badd38c639a245e1dd04786881fae1060fbd72d3ed419b2f0d38d6082dc9d67876c32ec65d77b5146dc898acf5b14df33f49306d539f6d84784e135d32d1807b37ce2a65fdd8c44a6b7191c09702d9f747471564346c465a42b9abbb4dfa1bc5f7fb2653886ab93ab5d7c779b796f87199e033ce012970d565d91cf9063d6149a1f8117bd27a209d6350b10f5c8f8cf841755c253276460be8c7681f5357e07d2e0c0f9cfe8eefbb983daa9c0e4bfb14a29a534b1c6d00fc16fe8a762d109ad0e0370c7c6926e854aac4dc4821be07f826157b576d0a217d74d5675d7b32eb78b50e00550d5c2ed14a445ae13cff8eff32ba7a7dd502d145481bcd18161cf1df540da8a2c2f82d542b0e05848d102e2f04239982b48ba7522a83dfc8b1308d7a8c1282c569b93da5c18ed649ebd4c2c79437db4611a6a1373e805a3cb001c64130b7
Techniques (MITRE) (10)
Malware (1)
-
FamilyPublished 04/06/2024 15:58 · Modified 04/06/2024 15:58