216.73.217.22

Zharkbot Strings

· Published 03/09/2024 08:09 · Modified 03/09/2024 08:42

Export JSON

Essential information

Published
03/09/2024 08:09
Modified
03/09/2024 08:42
Tags
2024-09-03 amadey anti-analysis anti-sandbox c2 communication downloader persistence string encryption zharkbot
Related entities
2 observables, 9 techniques (mitre), 2 malware

Description

is a C++ with extensive and features. It uses in-line and API calls, making static and emulation analysis challenging. The malware performs sandbox detection by checking for specific usernames and hypervisors. It installs itself in the TEMP directory as 'explert.exe' and establishes via the RUNONCE registry key. builds its C2 data and communicates with the server at solutionhub.cc:443/socket/. The analysis reveals the malware's build version as 1.2.5B and provides insights into its installation, , and network communication methods.

External references