Tonto Team Using Anti-Malware Related Files for DLL Side-Loading - ASEC BLOG
Common Information
Type Value
UUID 4d2ea395-54f1-485f-914e-c232802f80b7
Fingerprint a6253b6b0cefb76f
Analysis status DONE
Considered CTI value 2
Text language
Published April 26, 2023, 8 a.m.
Added to db April 26, 2023, 1:47 a.m.
Last updated Nov. 14, 2024, 10:55 p.m.
Headline Tonto Team Using Anti-Malware Related Files for DLL Side-Loading
Title Tonto Team Using Anti-Malware Related Files for DLL Side-Loading - ASEC BLOG
Detected Hints/Tags/Attributes 36/2/16
Source URLs
RSS Feed
Attributes
Details Type #Events CTI Value
Details Domain 3
hairouni.serveblog.net
Details File 6
presentationsettings.exe
Details File 9
slc.dll
Details File 4
1.chm
Details File 3
himtraylcon.exe
Details File 2
kcaseagent64.exe
Details File 15
wsc_proxy.exe
Details File 18
wsc.dll
Details md5 2
59f7a3fe0453ca6d27ba3abe78930fdf
Details md5 2
fe1161885005ac85f89accf703ce27bb
Details md5 2
d5e6dc253a5584b178ae3c758120da4d
Details IPv4 3
92.38.135.212
Details IPv4 3
45.133.194.135
Details MITRE ATT&CK Techniques 227
T1574.002
Details Url 3
https://92.38.135.212/fuat/himtraylcon.exe
Details Url 2
http://45.133.194.135:8080/fuat/kcaseagent64.exe