Water Hydra APT组织最新攻击链攻击样本详细分析
Tags
Common Information
Type Value
UUID 8d9a54e5-1d16-48dd-9edb-f9872767a821
Fingerprint ebaef9c7db264ac8
Analysis status DONE
Considered CTI value 0
Text language
Published Oct. 12, 2024, midnight
Added to db Oct. 12, 2024, 12:51 p.m.
Last updated Dec. 20, 2024, 2:57 p.m.
Headline Water Hydra APT组织最新攻击链攻击样本详细分析
Title Water Hydra APT组织最新攻击链攻击样本详细分析
Detected Hints/Tags/Attributes 2/0/10
Attributes
Details Type #Events CTI Value
Details Domain 94
xz.aliyun.com
Details Domain 1
20.info
Details File 3
7.msi
Details File 1
20.inf
Details File 9
o.txt
Details File 1
恶意模块读取同目录下的wmfile01.tmp
Details File 1
在指定的目录下解密生成wmfile01.dll
Details File 1
调用wmfile01.dll
Details File 1
并将恶意代码注入到windbvers.exe
Details Url 1
https://xz.aliyun.com/t/14711