Tonto Team Using Anti-Malware Related Files for DLL Side-Loading - ASEC BLOG
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Dll Side-Loading - T1574.002 Malware - T1587.001 Malware - T1588.001 Software - T1592.002 Connection Proxy - T1090 Dll Side-Loading - T1073 |
Common Information
Type | Value |
---|---|
UUID | 4d2ea395-54f1-485f-914e-c232802f80b7 |
Fingerprint | a6253b6b0cefb76f |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | April 26, 2023, 8 a.m. |
Added to db | April 26, 2023, 1:47 a.m. |
Last updated | Nov. 14, 2024, 10:55 p.m. |
Headline | Tonto Team Using Anti-Malware Related Files for DLL Side-Loading |
Title | Tonto Team Using Anti-Malware Related Files for DLL Side-Loading - ASEC BLOG |
Detected Hints/Tags/Attributes | 36/2/16 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/51746/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 17 | ✔ | ASEC | https://asec.ahnlab.com/en/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 3 | hairouni.serveblog.net |
|
Details | File | 6 | presentationsettings.exe |
|
Details | File | 9 | slc.dll |
|
Details | File | 4 | 1.chm |
|
Details | File | 3 | himtraylcon.exe |
|
Details | File | 2 | kcaseagent64.exe |
|
Details | File | 15 | wsc_proxy.exe |
|
Details | File | 18 | wsc.dll |
|
Details | md5 | 2 | 59f7a3fe0453ca6d27ba3abe78930fdf |
|
Details | md5 | 2 | fe1161885005ac85f89accf703ce27bb |
|
Details | md5 | 2 | d5e6dc253a5584b178ae3c758120da4d |
|
Details | IPv4 | 3 | 92.38.135.212 |
|
Details | IPv4 | 3 | 45.133.194.135 |
|
Details | MITRE ATT&CK Techniques | 227 | T1574.002 |
|
Details | Url | 3 | https://92.38.135.212/fuat/himtraylcon.exe |
|
Details | Url | 2 | http://45.133.194.135:8080/fuat/kcaseagent64.exe |