THREAT OPS › Threat News › Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-59ff56f1-58f2-4a93-a788-cf54d4a7c861"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Screen CaptureT1113
- Acquire InfrastructureT1583
- Match Legitimate Resource Name or LocationT1036.005
- Service StopT1489
- Malicious FileT1204.002
- Windows PermissionsT1222.001
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- MsiexecT1218.007
- DomainsT1583.001
- MasqueradingT1036
- Process InjectionT1055
- System Binary Proxy ExecutionT1218
- SMB/Windows Admin SharesT1021.002
- Modify RegistryT1112
- File and Directory Permissions ModificationT1222
- Command and Scripting InterpreterT1059
- Malicious LibraryT1204.005
- Web ServicesT1583.006
- PowerShellT1059.001
- Web ServicesT1584.006
- Hijack Execution FlowT1574
- Non-Standard PortT1571
- Social MediaT1593.001
- ImpersonationT1684.001
- Windows Command ShellT1059.003
- Ingress Tool TransferT1105
- Inhibit System RecoveryT1490
- Acquire InfrastructureAML.T0008
- Command and Scripting InterpreterAML.T0050
- ImpersonationAML.T0073
- MasqueradingAML.T0074
Indicators of compromise
- 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8sha256
- 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17sha256
- 676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7sha256
- c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdfsha256
- c6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73fafsha256
- f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81bsha256
- e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3sha256
- aea879a0689d4f0510d63043570474978bf51013a2d5b5d9154ec1238d8b2da5sha256
- 6dacf28164ad873fe98c5d583e73531cded11dfcb2955146b1adc333b3510002sha256
- http://www.gehie246.com/712downurl
- https://www.gehie246.com/712downurl
- https://otx.alienvault.com/pulse/6a36fe5a3c1568785b59c4d7url
- https://bazaar.abuse.ch/sample/aea879a0689d4f0510d63043570474978bf51013a2d5b5d9154ec1238d8b2da5url
- https://bazaar.abuse.ch/sample/6dacf28164ad873fe98c5d583e73531cded11dfcb2955146b1adc333b3510002url
- https://microsoft.github.io/zerotrustassessment/url
- 3.8.0.0ipv4
- 47.239.232.245ipv4
- 47.243.218.255ipv4
- 103.156.25.35ipv4
- 103.183.3.162ipv4
- 202.95.14.237ipv4
- 161.248.87.157ipv4
- 43.99.100.248ipv4
- 47.239.175.163ipv4
- 47.86.205.97ipv4
- com.cndomain
- hl.cndomain
- pc-razerzone.com.cndomain
- yimxg25tiy.comdomain
- cc8ttkv35b.comdomain
- n7b8t85zsg.comdomain
- kaspersky-lab.hl.cndomain
- calibre-ebook.com.cndomain
- app-microsoft-edge.com.cndomain
- sejda.hl.cndomain
- translate-youdao.hl.cndomain
- zh-diskgenius.com.cndomain
- baidu-pan.com.cndomain
- ocam-pc.com.cndomain
- draw.iodomain