A .NET malware abusing legitimate ffmpeg | Malwarebytes Labs
Tags
country: | France |
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | 1bff2318-17b6-4e15-a42c-175edb4d1846 |
Fingerprint | 9c203e1aacb32c85 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 12, 2017, midnight |
Added to db | Sept. 26, 2022, 9:31 a.m. |
Last updated | Nov. 8, 2024, 11:37 a.m. |
Headline | A .NET malware abusing legitimate ffmpeg |
Title | A .NET malware abusing legitimate ffmpeg | Malwarebytes Labs |
Detected Hints/Tags/Attributes | 37/3/16 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 30 | www.sysinternals.com |
|
Details | File | 2 | remotedesktop.dll |
|
Details | File | 2 | processmanager.dll |
|
Details | File | 96 | rar.exe |
|
Details | File | 3 | ffmpeg.exe |
|
Details | File | 1 | dshownet.dll |
|
Details | File | 1 | capture.dll |
|
Details | File | 50 | www.sys |
|
Details | File | 1 | remotedesk.dll |
|
Details | md5 | 1 | 2a07346045558f49cad9da0d249963f1 |
|
Details | md5 | 1 | 049af19db6ddd998ac94be3147050217 |
|
Details | md5 | 1 | 9c9f9b127becf7667df4ff9726420ccb |
|
Details | md5 | 1 | 85d35dd33f898a1f03ffb3b2ec111132 |
|
Details | md5 | 1 | e907ebeda7d6fd7f0017a6fb048c4d23 |
|
Details | md5 | 1 | d628d2a9726b777961f2d1346f988767 |
|
Details | IPv4 | 1 | 37.187.92.171 |