Crimson Palace returns: New Tools, Tactics, and Targets 
Common Information
Type Value
UUID 4fcca2c6-24a8-4854-a37d-4c1d43151810
Fingerprint 34308d918825940d
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 10, 2024, 10 a.m.
Added to db Sept. 10, 2024, 12:57 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Crimson Palace returns: New Tools, Tactics, and Targets
Title Crimson Palace returns: New Tools, Tactics, and Targets 
Detected Hints/Tags/Attributes 131/4/96
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 183 Sophos News https://news.sophos.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 3
cve-2023-38817
Details Domain 1
172.xx.xxx
Details Domain 1
dmsz.org
Details Domain 1
cancelle.net
Details Domain 1
gandeste.net
Details Domain 1
172.xx.xxx.xxx
Details Domain 6
windows.data
Details Domain 3
echo.ac
Details Domain 1
gsenergyspeedtest.com
Details Domain 1
172.xxx.xxx.xxx
Details File 74
mstsc.exe
Details File 4
ptwatchdog.exe
Details File 1
tmpblglog.dll
Details File 41
mscorsvw.exe
Details File 4
mscorsvc.dll
Details File 1
c:\programdata\mios.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 118
sc.exe
Details File 1
c:\system32\swprv.dll
Details File 1
swprvs.dll
Details File 5
appmgmt.dll
Details File 1122
svchost.exe
Details File 1
swprv.dll
Details File 263
iexplore.exe
Details File 1018
rundll32.exe
Details File 5
backgroundtaskhost.exe
Details File 1
doc20231100001603kmap.pdf
Details File 2
c:\windows\temp\1.txt
Details File 2125
cmd.exe
Details File 1
sophoshealthclient.exe
Details File 18
c:\windows\syswow64\rundll32.exe
Details File 2
c:\windows\syswow64\windows.dat
Details File 1
devices.config
Details File 1
c:\programdata\vmnat\test\log.ini
Details File 2
asoc.exe
Details File 1
33.bat
Details File 1
c:\programdata\kaba.exe
Details File 1
c:\programdata\asoc.exe
Details File 1
kaba.exe
Details File 1
mico.sys
Details File 1
echo_driver.sys
Details File 3
sophosfilescanner.exe
Details File 1
c:\users\public\log.ini
Details File 2
ssoc.exe
Details File 4
c:\programdata\conhost.exe
Details File 1
msntlm.dll
Details File 40
libcef.dll
Details File 3
jcef_helper.exe
Details File 1
c:\perflogs\conhost.exe
Details File 1
c:\perflogs\wsoc.exe
Details File 1
wsoc.exe
Details File 142
wmiprvse.exe
Details File 4
jconsole.exe
Details File 19
jli.dll
Details File 1
execit.dll
Details File 4
log.ini
Details File 2
scylla_x64.exe
Details File 40
ollydbg.exe
Details File 16
idaq64.exe
Details File 11
immunitydebugger.exe
Details File 2
unpacked.exe
Details File 2
reshacker.exe
Details File 1
log.bin
Details File 6
identity_helper.exe
Details File 2
msedge_elf.dll
Details File 1
c:\windows\temp\temp.log
Details File 199
firefox.exe
Details File 1
fireconf.exe
Details File 2
pp.exe
Details File 1
c:\users\public\temp.log
Details File 1
c:\users\public\pp.exe
Details File 137
conhost.exe
Details File 1
r2.exe
Details File 4
r1.exe
Details File 1
c:\users\public\rsndispot.sys
Details File 1
c:\users\public\kl.sys
Details File 16
2.bat
Details File 1
c:\users\public\dd.dat
Details File 1
c:\users\public\log.dat
Details IPv4 1
178.128.221.202
Details IPv4 1
103.19.16.248
Details IPv4 1
103.56.5.224
Details IPv4 1
49.157.28.114
Details IPv4 1
123.253.35.100
Details IPv4 1
107.148.41.114
Details IPv4 1
141.136.44.219
Details IPv4 1
64.176.50.42
Details IPv4 3
198.13.47.158
Details IPv4 1
45.77.46.245
Details IPv4 1
64.176.37.107
Details Mandiant Temporary Group Assumption 4
TEMP.LOG
Details Pdb 1
e:\masol_https190228\x64\release\masol.pdb
Details Threat Actor Identifier - APT 522
APT41
Details Threat Actor Identifier by Sophos 5
STAC1248
Details Threat Actor Identifier by Sophos 5
STAC1870
Details Threat Actor Identifier by Sophos 5
STAC1305