How Watchdog smuggles malware into your network as uninteresting photos
Common Information
Type Value
UUID 14cc754f-a0da-485c-abb2-078fd0a23380
Fingerprint b401cf6b25f30ec7
Analysis status DONE
Considered CTI value 2
Text language
Published July 15, 2022, midnight
Added to db Aug. 31, 2024, 9:57 a.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline How Watchdog smuggles malware into your network as uninteresting photos
Title How Watchdog smuggles malware into your network as uninteresting photos
Detected Hints/Tags/Attributes 53/3/24
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 326 Lacework Blog https://www.lacework.com/lacework_blog.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 3
newinit.sh
Details Domain 1
recipt-picture.oss-cn-hongkong.aliyuncs.com
Details Domain 4
is.sh
Details Domain 30
init.sh
Details Domain 1
guli-edut.oss-cn-shanghai.aliyuncs.com
Details Domain 1
newiniti.sh
Details Domain 7
kill.sh
Details Domain 4
rs.sh
Details File 1
indexis.png
Details File 1
indexni.png
Details File 1
indexi.png
Details File 1
indexrs.png
Details IPv4 3
106.15.74.113
Details MITRE ATT&CK Techniques 26
T1027.003
Details MITRE ATT&CK Techniques 66
T1584
Details MITRE ATT&CK Techniques 460
T1059.001
Details Url 1
https://recipt-picture.oss-cn-hongkong.aliyuncs.com/mall-img/indexis.png
Details Url 1
https://recipt-picture.oss-cn-hongkong.aliyuncs.com/mall-img/indexni.png
Details Url 1
https://guli-edut.oss-cn-shanghai.aliyuncs.com/2020/06/04/indexni.png
Details Url 1
https://recipt-picture.oss-cn-hongkong.aliyuncs.com/mall-img/indexi.png
Details Url 1
https://guli-edut.oss-cn-shanghai.aliyuncs.com/2020/06/04/indexi.png
Details Url 1
https://recipt-picture.oss-cn-hongkong.aliyuncs.com/mall-img/indexrs.png
Details Yara rule 1
rule image_bash {
	strings:
		$imgpng = { 89 50 4E 47 0D 0A }
		$imgjpg = { FF D8 FF }
		$shell = "!/bin/sh"
	condition:
		(($shell) and ($imgpng at 0 or $imgjpg at 0))
}
Details Yara rule 1
rule image_curl {
	strings:
		$imgpng = { 89 50 4E 47 0D 0A }
		$imgjpg = { FF D8 FF }
		$url = " http://"
		$curl = "curl "
		$wget = "wget "
	condition:
		(($url) and ($curl or $wget) and ($imgpng at 0 or $imgjpg at 0))
}