This report outlines activity by APT41, including newly identified malicious samples, accompanying YARA rules for detection, and practical TI lookup queries to identify related threats. These findings provide actionable insights for detecting and mitigating APT41’s evolving tactics. It is not an in-depth analysis of APT41’s tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
APT41 is a Chinese state-sponsored cyber espionage group with dual motives: conducting cyber espionage and financially motivated cybercrime. The group primarily targets sectors such as telecommunications, healthcare, manufacturing, and transportation. Geographically, its operations span Asia, Europe, and the Middle East, with notable activity in countries like Germany, Italy, and the United Kingdom. APT41 is known for its advanced techniques and tools, focusing on intellectual property theft, surveillance, and establishing strategic access to targeted systems.
China
Espionage
Financial gain
2012
SHA-256: c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db
Sample: ANY.RUN
SHA-256: 33fd050760e251ab932e5ca4311b494ef72cee157b20537ce773420845302e49
Sample: ANY.RUN
SHA-256: 22a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86
Sample: ANY.RUN
SHA-256: 2e62d6c47c00458da9338c990b095594eceb3994bf96812c329f8326041208e8
Sample: ANY.RUN
SHA-256: 407ab8618fed74fdb5fd374f3ed4a2fd9e8ea85631be2787e2ad17200f0462b8
Sample: ANY.RUN
SHA-256: 187b6a4c6bc379c183657d8eafc225da53ab8f78ac192704b713cc202cf89a17
Sample: ANY.RUN
SHA-256: 2801a3cc5aed8ecb391a9638a3c6f8db58ca3002e66f11bf88f8c7c2e5a6b009
Sample: ANY.RUN
SHA-256: 7910478d53ab5721208647709ef81f503ce123375914cd504b9524577057f0ec
Sample: ANY.RUN
APT41 compromised Taiwanese government-affiliated research institute
SHA-256: 2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9
Sample: ANY.RUN
SHA-256: c3efcb6efad675613721910a783389a646b2d138c7721df9849b28952d25bcfc
Sample: ANY.RUN
Before execution, the PowerShell backdoor creates a mutex named “v653Bmua-53JCY7Vq-tgSAaiwC-SSq3D4b6. Malware commonly uses mutexes to avoid multiple infections of the same system.
The PowerShell backdoor adds its payload to the HKCU\Environment\UserInitMprLogonScript registry key to establish persistence and uses forfiles.exe to execute its commands. This ensures that the malicious payload runs automatically every time the user logs into the system.
With the following TI lookup queries, we can search through public tasks and identify these malicious activities.
TI lookup:
syncObjectName:"v653Bmua-53JCY7Vq-tgSAaiwC-SSq3D4b6"
TI lookup:
registryKey:"HKEY_CURRENT_USER\\ENVIRONMENT" AND registryValue:"*forfiles.exe*"
bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428SHA-256: fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f
Sample: ANY.RUN
Melofee attempts to establish persistence by writing a command to execute itself into the system files /etc/rc.local or /etc/rc.d/rc.local when running with root privileges, ensuring automatic execution during system boot. If running as a regular user, it adds the command to .bash_profile, .bash_login, or .profile to achieve auto-execution upon user login. [T1037.004]
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
MITRE:"T1037.004" and filePath:"/etc/rc.local"
SHA-256: a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a
Sample: ANY.RUN
SHA-256: 2db4adf44b446cdd1989cbc139e67c068716fb76a460654791eef7a959627009
Sample: ANY.RUN
SHA-256: c40db0438a906eb0bec55093f1a0f2cc4cdc38104af0b4b4b3f18200a635c443
Sample: ANY.RUN
SHA-256: cf59cd171270ec9bc2baf618838eb57802cc9d48f64205da308406811dd4da92
5217b8552321556ea434474377cfcd02b69984cbf52b418673bd08279ca845d675bfb7d5199bf0c4e62525099b33e14fbfd6286bb39a0e24a2af28c63bd8e194f68ef9e40462c9760bf9c829edd9f4a95b1e8455291d99a1724327b9a7fc26164141c4b827ff67c180096ff5f2cc147472070b165d1f11bd4d009a81bf28a3e5b3067f382d70705d4c8f6977a7d7bee4f0953ed4a679b987a2da955788737602bc85062de0f70afd44bb072b0b71a8ccbcac2cbda36019776d7861f12d9b59c4294cc02db5a122e3a1bc4f07997956da0d068b6d0523f069d1ada59c12891c4af062183da590aba5e911d2392bc29181ns1[.]akacur.tkns2[.]akacur.tkorange-breeze-66bb[.]tezsfsoikdvd.workers.devwww[.]eloples.com393065ef9754e3f39b24b2d1051eab61ac125aea0b703de37980779599438b4a35f650c94faf6a2068e8238dd99edbeae584119a4766e6cf49093c666965c8bedc725f5e9b1ae062fbec86ee4d816b45a689e182fe33b9d564dddc35412ea0a7fcff642268898fcf65702a214aefbf9ee98b9e21928252332edf934f3d18ac21aca5c6daecf463012a09564764584937336a0d6f8cc92bf9740ce17de600463bcfce85548436fb89a83bf34dc17f325de4a4aafb49b8c86a5ac087ae342c0ee617d0ada8f5610ff29f2e8eaf0e3bb578f1769ad5a9dc44794895275c656ed4848222352a61eacca3a1c6517956aa0b559991ce9d2746313f505dbf04873370823bb44c0dd7f424864d76d4df09538cb60e74285f3359393e57f5d49c156aca47d72f202c1d684c9a19f075290a60920f6bc4a92ff4d2cfc9da91ae6a5d2ad3d595.164.16[.]231152.89.244[.]185hxxp[:]152.89.244.185/conn.exeAPT41 compromised Taiwanese government-affiliated research institute
w2[.]chatgptsfit.com2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9087c475a1b5b36b7939f5ff12dc711ba591dd2c4227ccaa28d322425ef4d0d4c2149d481b863bec2240ffb64c68f7fb437458885c903a7b0c21aa44f88a69d86eba3138d0f3d2385b55b08d8886b1018834d194440691d33d612402ba8a11d28983f4e4be2c2cd36da67723f6e87d86994531bb1ef8e82b3fd3a1c0d6d072a0abe7e1f1216ff707ad07d11e5d180fa1cbfba62f2e2414a20d827366bcc6be3c4756ceb563d9283df1fd03252aee9e9621cd2cc7ddb45f596e16660fed1dd64429dc827fb1c2e3c12ee39aa5ccf3b31f64051e0cdda9d2ac54caee6b235f52640abb2fe1f67a48b931258e47531884ca5502cec73996e686ca82eeba536258f6745.85.76[.]1058.64.204[.]145103.96.131[.]8445.85.76[.]18hxxps[:]www.nss.com.tw/p.ps1hxxps[:]www.nss.com.tw/1.htahxxp[:]103.56.114.69:8085/p.ps1hxxp[:]45.85.76.18:443/yPc1hxxps[:]www.nss.com.tw/calc.exehxxps[:]www.nss.com.tw/s.pngAPT41 Deploys DeepData Framework
c3995f28476f7a775f4c1e8be47c64a300e0f16535dc5ed665ba796f05f19f73b79629e820cdd36d0daed964a2c0338e125a1f90f08e226f52dc60070747c62eb523cdd1669dbd7ab68b43fd20f30a790ec0351876a0610958b9405468753a10ac7e20d4ddccc5e249ff0c1a72e394f9c1667a896995cf55b97b4f9fbf5de2fd2bfb82a43bb77127965a4011a87de845242b1fb98fd09085885be219e0499073041c13a29d3bee8d2e4bd9d8bde8152b5ac8305c1efcc198244b224e33635282735d59c0949e258501e177ec2dd5fbb60df9fa401ace08949b89077c6f0d41d088e5ca44189dabb4cec8a183f6268a42f3f92b2c6d7c722d7f55efd3dc5334c8213520170fc7113ac8f5e689f154f5c8074dd972584b56d820c19d84b7e5b477724351b5cc9ad496a6c9486b8ef34772f640590a90293f913f005e994717134b460f1a00002e1c713a7753293b4737e65d27d0b65667b109d66afca873c23894ccfd6ef35c718e2484b3727035d162b667f4b56df43324782d106f50ed1e3bcc55e2dbb906697dd1aff87ccf275efd06ee5e43bb21ea7865aef59513a858cf9f666a4c569d435d0e6bf9fa4d337d1bf014952b42cc6d20e797db6c9df92dd724cf59cd171270ec9bc2baf618838eb57802cc9d48f64205da308406811dd4da92a560931baa404189257ec9cbcc2b9449c579018218cc1d70c99b1d36dd292a0eefff4106cfd21a356b13a5a99c626a4f103f03b9491c0f1f5e135c1e3c84e76c37a1ffaba2e3ea9a7b2aa272b0587826cc0b5909497d3744ec8c114b504d2544119.147.213[.]48202.43.239[.]13103.255.176[.]176hxxp[:]119.147.213.48:28992/asdgdsfdsfasd/frame.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/OutlookX32.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/SocialSoft.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/ChatIndexedDb.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/ProductList.dllhxxp[:]202.43.239.13:28992/asdgdsfdsfasd/appdata.dllhxxp[:]202.43.239.13:28992/asdgdsfdsfasd/ChatIndexedDb.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/WebBrowser.dllhxxp[:]202.43.239.13:28992/asdgdsfdsfasd/SocialSoft.dllhxxp[:]103.255.176.176:28992/asdgdsfdsfasd/Telegram.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/data.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/localupload.exehxxp[:]119.147.213.48:28992/asdgdsfdsfasd/Tdm.dllhxxp[:]119.147.213.48:28992/asdgdsfdsfasd/Audio.dllhxxp[:]202.43.239.13:28992/asdgdsfdsfasd/SystemInfo.dllEarth Longzhi Returns with New Tricks
www[.]updateforhours.comevnpowerspeedtest[.]comasis[.]downloadwindowsupdate.codns[.]eudnslog.com7910478d53ab5721208647709ef81f503ce123375914cd504b9524577057f0ec8327cd200cf963ada4d2cde942a82bbed158c008e689857853262fcda91d14a416887b36f87a08a12fe3b72d0bf6594c3ad5e6914d26bff5e32c9b44acfec04021ffa168a60f0edcbc5190d46a096f0d9708512848b88a50449b7a8eb19a91ed39de0389d3186234e544b449e20e48bd9043995ebf54f8c6b33ef3a4791b653775a51d1f1dd26501e02907117f0f4dd91469c7dd30d73a715f52785ea3ae93c8e654ecc10ce3df9f33d1e7c86c704cfdc9cf6c6f49aa11af2826cbc4b659e97c4399c5d9745fa2f83bd1223237bdabbfc84c9c77bacc500beb25f8ba9df30379942b93529c45f27cdbd9bbcc884a362438624b8ca6b721d51036ddaebc750d8eebf461be88903ffc19363434944ad31e36ef900b644efa31cde84ff99f3d6aed9eceba551baafe79b45d412c5347a3d2a07de00cc23923b7dee1616dee087905ef8e658cd71c3af7c77ab21d2347c7d41764a68141551938b885da41971dd733630bb985d2df8e539e35f2da696096e431b3274428f80bb6601bbf4b1d45f71e198.13.47[.]15864.227.164[.]34207.148.115[.]125194.31.53[.]128Melofee: Unveiling a New Linux Threat
help[.]git1ab.comstock[.]awszonwork.comabout[.]git1ab.comdns[.]cloudf1are.comcdn4[.]cloudf1are.comtest[.]yuanta.devwww[.]data-yuzefuji.comcloudf1are[.]comssm[.]awszonwork.comcdn3[.]cloudf1are.comdgbyem[.]comdev[.]yuanta.devupdate[.]ankining.comvt[.]livehost.livecdn2[.]cloudf1are.comus[.]securitycloud-symantec.icudns2[.]cloudf1are.comcdn[.]cloudf1are.comwww[.]git1ab.com330a61fa666001be55db9e6f286e29cce4af7f79c6ae267975c19605a2146a212db4adf44b446cdd1989cbc139e67c068716fb76a460654791eef7a9596270092801a3cc5aed8ecb391a9638a3c6f8db58ca3002e66f11bf88f8c7c2e5a6b009ad979716afbce85776251d51716aeb00665118fb350038d150c129256dd6fc5f8d855c28744dd6a9c0668ad9659baf06e5e448353f54d2f99beddd21b41390b73ca39774a4405537674673227940e306cf5e8cd8dfa1f5fc626869738a489c3d22fd67457274635db7dd679782e002009363010db66523973b4748d5778b1a2a758b0934b7adddb794951d15a6ddcace1fa523e814aa40b55e2d071cf2df81f0c36ab5108491f4969512f4d35e0d42b3d371033c8ccf03e700c60fb98d5a95f83535f45bbfafda863665c41d97d894c39277dfd9af1079581d28015f76669b88a37661830859ca440d777af0bfa829b01d276bb1f81fe14b1485fa3c09f5f2867684e1dfaeb2e7c8fd1c9bd65041b705bc92a87d9e11e327309f6c21b5e7ad971f9e4bfb25622eab6c33da7da9be6c51cf8bf1a284ee1c1703a3cee445bc8cd9899ef7681982941b233e1ea3c1a6d5a4e90153bbb2809f70ee5f6fcece06cabc6e858c2c9ae20e3149cb0012ab9a24995aa331d2a818b127b2f517bc3aa745a069ff2f88c1f9007b80d591e9655cc61eaa4709ccd8b3aa6ec15e3aa46b9098bd378acfdbcec039cfe7287faac184adf6ad525b201cf781db9082b784c9c75c997149cdb130e1a52862168856eae01791cc3d9632287f990d90da0cce1dc7c6b9a62b67596640a3ebadd288e733f933ff581cc1822d6871351d82bd7472655bb5617f9add4c27f3bb91a32fee007cce01f5a51deaf42e75e6cec3e71afe2ba9672e62d6c47c00458da9338c990b095594eceb3994bf96812c329f8326041208e8f49f1b2cc52623624fdd3d636056b8a80705f6456a3d5a676e3fb78749bdd281407ab8618fed74fdb5fd374f3ed4a2fd9e8ea85631be2787e2ad17200f0462b85861584bb7fa46373c1b1f83b1e066a3d82e9c10ce87539ee1633ef0f567e743f3e35850ce20dfc731a6544b2194de3f35101ca51de4764b8629a692972bef68ad5bc6c4e653f88c451f6f6375516cc36a8fa03dd5a4d1412a418c91d4f9bec8187b6a4c6bc379c183657d8eafc225da53ab8f78ac192704b713cc202cf89a17a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a2c1a6fe08c8cbdc904809be4c12b520888da7f33123d1656a268780a9be45e203c1842d29a3445bd3b85be486e49dba36b8b5ad55841c0ce00630cb83386881d103.87.10[.]100185.145.128[.]90173.209.62[.]187173.209.62[.]186167.172.73[.]20247.243.51[.]98173.209.62[.]189202.182.101[.]174156.67.208[.]1925.61.57[.]8038.54.30[.]39173.209.62[.]190144.202.112[.]187147.139.28[.]254173.209.62[.]188Espionage Campaign with Voldemort
pants-graphs-optics-worse[.]trycloudflare.comrecall-addressed-who-collector[.]trycloudflare.cominvasion-prisoners-inns-aging[.]trycloudflare.comways-sms-pmc-shareholders[.]trycloudflare.comfa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f3fce52d29d40daf60e582b8054e5a6227a55370bed83c662a8ff2857b55f4cea6bdd51dfa47d1a960459019a960950d3415f0f276a740017301735b8580197280b3235db7e8154dd1b23c3bed96b6126d73d24769af634825d400d3d4fe8ddb9561e15a46f474255fda693afd644c8674912df495bada726dbe7565eae2284fbhxxps[:]//od.lk/s/OTRfODQ1NzA0Mjlf/einzelfragen_steuerbescheinigungen_de.pdfhxxps[:]//sheets.googleapis.com:443/v4/spreadsheets/16JvcER-0TVQDimWV56syk91IMCYXOvZbW4GTnb947eE/hxxps[:]//pubs.infinityfreeapp.com/Notice_pour_remplir_la_N%C2%B0_2044.htmlhxxps[:]//pubs.infinityfreeapp.com/SA150_Notes_2024.htmlhxxps[:]//pubs.infinityfreeapp.com/IRS_P966.htmlhxxps[:]//od.lk/s/OTRfODQ1NDc2MjZf/SA150_Notes_2024.pdfhxxps[:]//od.lk/s/OTRfODQ4ODE4OThf/logo.pnghxxps[:]//od.lk/s/OTRfODM5Mzc3NjFf/irs-p966.pdfhxxps[:]//resource.infinityfreeapp.com/0023012-317.htmlhxxps[:]//od.lk/s/OTRfODQ1Njk2ODVf/2044_4765.pdfhxxps[:]//od.lk/s/OTRfNzQ5NjQwOTJf/test.pnghxxps[:]//resource.infinityfreeapp.com/ABC_of_Tax.htmlhxxps[:]//od.lk/s/OTRfODQ5MzQ5Mzlf/ABC_of_Tax.pdfhxxps[:]//pubs.infinityfreeapp.com/La_dichiarazione_precompilata_2024.htmlhxxps[:]//od.lk/s/OTRfODM3MjM2NzVf/La_dichiarazione_precompilata_2024.pdfhxxps[:]//pubs.infinityfreeapp.com/Steuerratgeber.htmlhxxp[:]//83.147.243.18/p/Powershell Backdoor with Telegram C2
bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428d71f6fbc9dea34687080a2e12bf326966f6841d51294bd665261e07281459eebhxxps[:]//raw.githubusercontent.com/efimovah/abcd/main/xxx.gifhxxp[:]//ip-api.com/jsonicy-bar-c375.microsoft-updates[.]workers.devwww.mircoupdate.https443[.]netupdate-chrome.realgodad.workers[.]devtrack.cdn78544[.]ruwww.cdn7854.workers[.]devshrill-tooth-b557.vgfjuic.workers[.]devwww.sitennews[.]com0faddbe1713455e3fc9777ec45adf07b28e24f4c3ddca37586c2aa6b539898c022a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db73eaba82ef1c502448e533007e92b1afa879b09f85f28b71648668ea62839ff5c02accc26a389397fb172f83258baa8a974986ffd706ba708a3b0a679f61be5683de8917bf0ac1d670acf27431015215db872b7291979312dd65e30d99806abb7e63c6b9ab3b32beffbc1eb23d6ca7cc59616b0722f0dd4f0d893c0a1724f5d7073b35ecbd1833575fbfb1307654fc532fd938482e09426cfb0541ad87a04f75ec10a9396dca694fe64366e0dab82d046cf92457f97efd50a68ceb85adef6b741c88150ec85a07c3db5f18c5eedcb0b653467b897af01d690ed996e5e07ba8e38405d742405d3a6d3bda6bc49630dd5f3604a3d6ae27cbd533e425f8abbaafdccdcbd9c25e06ac6da5497fa19459d0007449ec1a3e6bc591334db6fb3598aecb166b6dcdac31f4bf51e4b20a7c3f7d4f7017ca0c30fa123d5591e25c3fa66107a50f85c71b69563ba42bf04c937e1063244ca4957231d3adac76f1c96ab42d3c07aa971f0791b06dd442d4c7a49c1d3d27a1cbb16602f731e870b5ef50edf69e3e52c310c6556367ff9e18448bc41719e603d1cbbdafdcba736c6565529617b6e4360c0aa995e6e896b22bb7725a6c9b189be8606e7cbbc8b6e80c606358649d21fc0f50d545c0a373380934dc61c423c8a31d8c3e6eae4f8a35149ad9962d887f24bc080281d250ec88493e5803e488721a17c9382cd54ba8dfbcb785f23a887463700ec5768d4af6549028465f978059611555aa8e22e2b7c664b1cdbfa9aeec5a96f42aeccdf9a3ae4c3650689606c8539fd65c0b47f30887afecb901be43ab56501167fe689fe55f6e6ddc3bb91952299bd5c3ef004b02bf1c3b4061c7cfe5f1360d4c299bb32e33e081115f2b520251a983af2ebc649b4b9b70308246fe7586e58a569c2a07d0b3a710616f48833a040bf3fc57628bbdec7fcb462d565a5.182.207[.]28212.87.212[.]11578.108.216[.]20Earth Baku Latest Campaign Analysis
icy-bar-c375.microsoft-updates.workers[.]devwww.mircoupdate.https443[.]netupdate-chrome.realgodad.workers[.]devtrack.cdn78544[.]ruwww.cdn7854.workers[.]devshrill-tooth-b557.vgfjuic.workers[.]devwww.sitennews[.]com0faddbe1713455e3fc9777ec45adf07b28e24f4c3ddca37586c2aa6b539898c022a50cea6ad67a7e8582d2cd4cdc3eaaf57c0fbe8cd062a9b15710166e255a86c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db73eaba82ef1c502448e533007e92b1afa879b09f85f28b71648668ea62839ff5c02accc26a389397fb172f83258baa8a974986ffd706ba708a3b0a679f61be5683de8917bf0ac1d670acf27431015215db872b7291979312dd65e30d99806abb7e63c6b9ab3b32beffbc1eb23d6ca7cc59616b0722f0dd4f0d893c0a1724f5d7073b35ecbd1833575fbfb1307654fc532fd938482e09426cfb0541ad87a04f75ec10a9396dca694fe64366e0dab82d046cf92457f97efd50a68ceb85adef6b741c88150ec85a07c3db5f18c5eedcb0b653467b897af01d690ed996e5e07ba8e38405d742405d3a6d3bda6bc49630dd5f3604a3d6ae27cbd533e425f8abbaafdccdcbd9c25e06ac6da5497fa19459d0007449ec1a3e6bc591334db6fb3598aecb166b6dcdac31f4bf51e4b20a7c3f7d4f7017ca0c30fa123d5591e25c3fa66107a50f85c71b69563ba42bf04c937e1063244ca4957231d3adac76f1c96ab42d3c07aa971f0791b06dd442d4c7a49c1d3d27a1cbb16602f731e870b5ef50edf69e3e52c310c6556367ff9e18448bc41719e603d1cbbdafdcba736c6565529617b6e4360c0aa995e6e896b22bb7725a6c9b189be8606e7cbbc8b6e80c606358649d21fc0f50d545c0a373380934dc61c423c8a31d8c3e6eae4f8a35149ad9962d887f24bc080281d250ec88493e5803e488721a17c9382cd54ba8dfbcb785f23a887463700ec5768d4af6549028465f978059611555aa8e22e2b7c664b1cdbfa9aeec5a96f42aeccdf9a3ae4c3650689606c8539fd65c0b47f30887afecb901be43ab56501167fe689fe55f6e6ddc3bb91952299bd5c3ef004b02bf1c3b4061c7cfe5f1360d4c299bb32e33e081115f2b520251a983af2ebc649b4b9b70308246fe7586e58a569c2a07d0b3a710616f48833a040bf3fc57628bbdec7fcb462d565a5.182.207[.]28212.87.212[.]11578.108.216[.]20time.qnapntp[.]comEarth Longzhi Returns with New Tricks
CVE-2018-5713APT41 compromised Taiwanese government-affiliated research institute
CVE-2018-0824
rule Windows_Trojan_DodgeBox_095012d2 {
meta:
author = "Elastic Security"
id = "095012d2-2804-44f5-b4a1-f9d9c028daf1"
fingerprint = "0797dbe75dea90df77d35d2d4a259b4402c041bc10f9e52df2ef80b2a5804c9f"
creation_date = "2024-07-11"
last_modified = "2024-07-26"
threat_name = "Windows.Trojan.DodgeBox"
reference_sample = "c6a3a1ea84251aed908702a1f2a565496d583239c5f467f5dcd0cfc5bfb1a6db"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
$a1 = { 53 4F 46 54 57 41 52 45 5C 4D 69 63 72 6F 73 6F 66 74 5C 43 72 79 70 74 6F 67 72 61 70 68 79 00 4D 61 63 68 69 6E 65 47 75 69 64 00 2E 70 64 61 74 61 }
$a2 = { 5C 00 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00 74 00 2E 00 4E 00 45 00 54 00 5C 00 61 00 73 00 73 00 65 00 6D 00 62 00 6C 00 79 00 5C 00 47 00 41 00 43 00 5F 00 4D 00 53 00 49 00 4C 00 5C 00 00 00 00 00 00 00 25 00 6C 00 6C 00 64 00 2E 00 6C 00 6F 00 67 }
$a3 = { 48 83 EC 20 48 63 51 3C 48 8B D9 33 F6 48 8D 3C 11 8B 8F 90 00 00 00 85 C9 74 21 8B 87 94 00 00 00 85 C0 74 17 44 8B C0 48 03 CB 33 D2 ?? ?? ?? ?? ?? 48 89 B7 90 00 00 00 8B 53 3C 48 63 FA }
$a4 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 48 63 51 3C 48 8B D9 33 F6 48 8D 3C 11 8B 8F 90 00 }
$a5 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 48 63 59 3C 33 D2 4C 8B C3 48 8B F1 E8 }
condition:
any of them
}
rule M_Hunting_Dropper_DUSTTRAP_1
{
meta:
author = "Mandiant"
description = "Detects the DUSTTRAP dropper (x64) based
on the use of CFG patching constants and argument construction
for payload entry-point"
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$cfg_patch_constant_1 = { 48 FF E0 CC 90 }
$cfg_patch_constant_2 = { 8B DA 48 8B F9 E8 }
$cfg_patch_constant_3 = { B8 48 8B 00 00 66 39 02 }
$cfg_patch_constant_4 = { 81 7A 07 48 8B D1 48 }
$log_format = "%lld.log" wide
condition:
uint16(0) == 0x5a4d and
all of ($cfg_patch_constant_*) and
$log_format
}
import "pe"
rule M_HUNTING_DUSTTRAP_PayloadFile {
meta:
author = "Mandiant"
description = "Detects executables containing a .lrsrc section
which may represent DUSTTRAP payloads"
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
condition:
for any i in (0..pe.number_of_sections - 1): (
uint32(pe.sections[i].raw_data_offset + 0) == 0x100 and
pe.sections[i].raw_data_size > uint32
(pe.sections[i].raw_data_offset + 0) and
pe.sections[i].name == ".lrsrc" and
uint32(pe.sections[i].raw_data_offset + 4) < 0x1000 and
uint32(pe.sections[i].raw_data_offset + 8) < 4
)
}
import "pe"
rule M_Hunting_DUSTPAN_CryptKeys {
meta:
author = "Mandiant"
description = "Attempts to detect executables containing known
DUSTPAN encryption keys within the .data section"
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$key_1 = {3BCF741BF6411C087415BA340000004C8D05F28
C0000488B4910E801F0FEFFB8}
$key_2 = {C4498BD6488BCFE848A5000084C07564488BCFE
8585C0000498B0F4C8B497045}
$key_3 = {A24299055F1F0C14CBDD0B01DFA64C34F5FD033
CA7F1AF30A0C75C57359D41E0}
condition:
filesize < 15MB and
for any i in (0..pe.number_of_sections - 1): (
pe.sections[i].name == ".data" and
any of ($key_*) in (pe.sections[i].raw_data_offset..
pe.sections[i].raw_data_offset + pe.sections[i].raw_data_size)
)
}
import "elf"
rule M_Hunting_Utility_Linux_SQLULDR2_1
{
meta:
author = "Mandiant"
description = "Detection of the Linux version of SQLULDR2."
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$name = "sqluldr2zip.c" ascii
$out = "uldrdata.%p.txt" ascii
$heading = "SQL*UnLoader: Fast Oracle Text Unloader" ascii
$p1 = "exec = the command to execute the SQLs" ascii
$p2 = "file = output file name(default: uldrdata.txt)" ascii
$p3 = "format = MYSQL: MySQL Insert SQLs, SQL: Insert SQLs" ascii
$p4 = "text = output type (MYSQL, CSV, MYSQLINS,
ORACLEINS, FORM, SEARCH)" ascii
$p5 = "rows = print progress for every given rows
(default, 1000000)" ascii
$p6 = "query = select statement" ascii
$p7 = "user = username/password@tnsname" ascii
condition:
(uint32(0) == 0x464c457f) and
$name and $out and $heading and (5 of ($p*)) and
for any i in (0 .. elf.symtab_entries):
(elf.symtab[i].name == "OCIServerAttach") and
for any i in (0 .. elf.symtab_entries):
(elf.symtab[i].name == "OCISessionBegin")
}
import "pe"
import "elf"
rule M_Hunting_Utility_SQLULDR2_1
{
meta:
author = "Mandiant"
description = "Detection of SQLULDR2."
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$win_name = "sqluldr2.exe" ascii
$elf_name = "sqluldr2zip.c" ascii
$out = "uldrdata.%p.txt" ascii
$heading = "SQL*UnLoader: Fast Oracle Text Unloader" ascii
$p1 = "exec = the command to execute the SQLs" ascii
$p2 = "file = output file name(default: uldrdata.txt)" ascii
$p3 = "format = MYSQL: MySQL Insert SQLs, SQL: Insert SQLs" ascii
$p4 = "text = output type (MYSQL, CSV, MYSQLINS,
ORACLEINS, FORM, SEARCH)" ascii
$p5 = "rows = print progress for every given rows
(default, 1000000)" ascii
$p6 = "query = select statement" ascii
$p7 = "user = username/password@tnsname" ascii
$import = "OCI.dll" ascii
condition:
(((uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and
pe.imports("OCI.dll","OCIServerAttach") and
pe.imports("OCI.dll","OCISessionBegin") and
$import and $win_name and
for all of ($p*) : ( @ > @heading )) or
((uint32(0) == 0x464c457f) and
$elf_name and
for any i in (0 .. elf.symtab_entries):
(elf.symtab[i].name == "OCIServerAttach") and
for any i in (0 .. elf.symtab_entries):
(elf.symtab[i].name == "OCISessionBegin"))) and
$out and $heading and (5 of ($p*))
}
rule M_Hunting_Uploader_PINEGROVE_1
{
meta:
author = "Mandiant"
description = "Hunting for PINEGROVE uploader
malware family."
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$s1 = "Config: `%v`" ascii
$s2 = "auth.json" ascii
$s3 = "sp=%v%v%x" ascii
$s4 = "Time: %v" ascii
$s5 = "/me/drive/root" ascii
$s6 = "OneDrive" ascii fullword
$s7 = "microsoft.graph.driveItemUploadableProperties" ascii
$s8 = "client_id=%v&client_secret=%v" ascii
$s9 = "http://localhost/onedrive-login" ascii
condition:
(
((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or
(uint32(0) == 0x464c457f) or
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
) and
(6 of them)
}
rule M_Hunting_Uploader_PINEGROVE_2
{
meta:
author = "Mandiant"
description = "Hunting for PINEGROVE uploader
malware family."
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$f1 = "main.AllFiles" ascii
$f2 = "main.Collect" ascii
$f3 = "main.ConfigInit" ascii
$f4 = "main.ConfigRead" ascii
$f5 = "main.ConfigSave" ascii
$f6 = "main.ConfigUpdate" ascii
$f7 = "main.Exit" ascii
$f8 = "main.FileRange" ascii
$f9 = "main.FileReader" ascii
$f10 = "main.FileStatus" ascii
$f11 = "main.FormatRemoteFilePath" ascii
$f12 = "main.GetFileName" ascii
$f13 = "main.GetReomtePath" ascii
$f14 = "main.Header" ascii
$f15 = "main.init.0" ascii
$f16 = "main.InitFile" ascii
$f17 = "main.IsFolder" ascii
$f18 = "main.main" ascii
$f19 = "main.PreLoad" ascii
$f20 = "main.Range2Int" ascii
$f21 = "main.RemainTime" ascii
$f22 = "main.SessionCreate" ascii
$f23 = "main.ShowBar" ascii
$f24 = "main.StringChecker" ascii
$f25 = "main.Task" ascii
$f26 = "main.TaskFail" ascii
$f27 = "main.ThreadUpload" ascii
$f28 = "main.Timer" ascii
$f29 = "main.TimeUnix" ascii
$f30 = "main.Upload" ascii
$f31 = "main.Upload.func1" ascii
$f32 = "main.Uploading" ascii
$version = "go1.13.1"
condition:
(
((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or
(uint32(0) == 0x464c457f) or
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
) and
$version and (25 of ($f*))
}
rule M_Hunting_Uploader_PINEGROVE_3
{
meta:
author = "Mandiant"
description = "Hunting for PINEGROVE uploader
malware family."
disclaimer = "This rule is meant for hunting and is not
tested to run in a production environment."
strings:
$s1 = "RefreshToken"
$s2 = "RefreshInterval"
$s3 = "ThreadNum"
$s4 = "BlockSize"
$s5 = "SigleFile"
$s6 = "MainLand"
$s7 = "MSAccount"
$anchor1 = "driveItemUploadableProperties"
$anchor2 = "client_id"
$anchor3 = "client_secret"
$anchor4 = "onedrive-login"
$anchor5 = "authorization_code"
condition:
(
((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) or
(uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or
(uint32(0) == 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or
(uint32(0) == 0x464c457f) or
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
) and
(5 of ($s*)) and
(4 of ($anchor*))
}
Powershell Backdoor with Telegram C2
rule APT41_Powershell_Backdoor
{
meta:
author = "seyitsec"
date = "2023-04-22"
hash =
"bb3d35cba3434f053280fc2887a7e6be703505385e184da4960e8db533cf4428"
strings:
str1= ”C:\Windows\system32\forfiles.exe /p c:\windows\system32
/m notepad.exe /c "cmd.exe /c whoami >> %appdata%\z.abcd”
str2=
”5621584862:AAGG6WcTvFu7ADpnMT42PqwOoKfTqMDQKkQ::5028607068”
str3= ”Software\Microsoft\Windows\CurrentVersion\RunOnce”
condition:
all of ($str*)
}
APT41 Deploys DeepData Framework
rule DeepData_Spy_tool {
meta:
description = "Rule to detect LightSpy-DeepData Windows files"
author = "The BlackBerry Research and Intelligence Team"
last_modified = "2024-11-12"
version = "1.0"
strings:
$a1 = {78 6d 68 5f 6d 69 71 75 5f 6b 65 79 5c 78 6d 68 5c e5 af 86} // \xmh_miqu_key\xmh\密
$a2 = "CodeS\\compile\\tg471\\desktop" ascii wide
$a3 = "zyx\\dll\\ProductList\\Debug" ascii wide
$a4 = "Users\\GT1\\source\\repos\\Audio_miqu" ascii wide
$a5 = "\\Code\\OtherWork\\DeepDataH\\" ascii wide
$a6 = "\\tmpWork\\deepdata-v2\\deepdata" ascii wide
$a7 = "\\Code\\project\\MiQuH\\MiQuH" ascii wide
$b1 = "WiFi Tool ExecuteCommand without" ascii wide
$b2 = "\\zyx\\dll\\Dll1\\Debug" ascii wide
condition:
uint16(0) == 0x5a4d and (filesize < 25000KB) and ((any of ($a*)) or (all of ($b*)))}
rule Linux_Rootkit_Melofee_25d42bdd {
meta:
author = "Elastic Security"
id = "25d42bdd-f6ee-458c-a102-7123225f0be2"
fingerprint = "964cf1d468b829064c681c6b22bce00c4ef3536243fc5d1bac16879e0b68d9b2"
creation_date = "2024-11-14"
last_modified = "2024-11-22"
threat_name = "Linux.Rootkit.Melofee"
reference_sample = "5830862707711a032728dfa6a85c904020766fa316ea85b3eef9c017f0e898cc"
severity = 100
arch_context = "x86, arm64"
scan_context = "file, memory"
license = "Elastic License v2"
os = "linux"
strings:
$str1 = "hide_proc"
$str2 = "find_hide_name"
$str3 = "hide_module"
$str4 = "unhide_chdir"
$str5 = "hide_content"
$str6 = "hidden_chdirs"
$str7 = "hidden_tcp_conn"
$str8 = "HIDETAGOUT"
$str9 = "HIDETAGIN"
condition:
4 of them
}
rule Linux_Trojan_Melofee_c23d18f3 {
meta:
author = "Elastic Security"
id = "c23d18f3-caac-4d8a-8ecd-d1b831723648"
fingerprint = "95bd1092104aa028b65b92d3dcf6af6deb019d00ef09e9c6570da39737fe3525"
creation_date = "2024-11-14"
last_modified = "2024-11-22"
threat_name = "Linux.Trojan.Melofee"
reference_sample = "b0abf6691e769ead1f11cfdcd300f8cd5291f19059be6bb40d556f793b1bc21e"
severity = 100
arch_context = "x86, arm64"
scan_context = "file, memory"
license = "Elastic License v2"
os = "linux"
strings:
$str1 = "hide ok"
$str2 = "show ok"
$str3 = "kill ok"
$str4 = "wwwwwww"
$str5 = "[md]"
$str6 = "87JoENDi"
condition:
4 of them
}
Melofee: Unveiling a New Linux Threat
rule UNK_APT_MelofeeImplant {
meta:
author = "Exatrack"
date = "2023-03-03"
update = "2023-03-03"
description = "Detects the Melofee implant"
tlp = "CLEAR"
sample_hash = "a5a4284f87fd475b9474626040d289ffabba1066fae6c37bd7de9dabaf65e87a,f3e35850ce20dfc731a6544b2194de3f35101ca51de4764b8629a692972bef68,8d855c28744dd6a9c0668ad9659baf06e5e448353f54d2f99beddd21b41390b7"
strings:
$str_melofee_implant_01 = "10PipeSocket"
$str_melofee_implant_02 = "ikcp_ack_push"
$str_melofee_implant_03 = "TLSSocketEE"
$str_melofee_implant_04 = "/tmp/%s.lock"
$str_melofee_implant_05 = "neosmart::WaitForMultipleEvents"
$str_melofee_implant_06 = "9TLSSocket"
$str_melofee_implant_07 = "7VServer"
$str_melofee_implant_08 = "N5boost6detail13sp_ms_deleterI13UdpSocketWrapEE"
$str_melofee_implant_09 = "UdpServerWrap"
$str_melofee_implant_10 = "KcpUpdater"
$str_melofee_implant_11 = "SelfForwardServer"
$str_command_parsing_01 = {3? 01 00 05 00 ?? ?? ?? ?? 00 00 3? 01 00 05 00 ?? ?? 3? 05 00 04 00}
$str_command_parsing_02 = {3? 04 00 04 00 ?? ?? ?? ?? 00 00 3? 04 00 04 00 ?? ?? 3? 05 00 01 00}
$str_command_parsing_03 = {3? 01 00 07 00 ?? ?? ?? ?? 00 00 3? 01 00 09 00 ?? ?? ?? ?? ?? 00 3? 01 00 06 00 }
condition:
3 of them
}
rule UNK_APT_Melofee_Installer {
meta:
author = "Exatrack"
date = "2023-03-15"
update = "2023-03-15"
description = "Detects the installer for melofee malware"
score = 80
tlp = "AMBER"
source = "Exatrack"
sample_hash = "758b0934b7adddb794951d15a6ddcace1fa523e814aa40b55e2d071cf2df81f0"
strings:
$str_melofee_installer_01 = "#Script for starting modules"
$str_melofee_installer_02 = "#End script"
$str_melofee_installer_03 = "/etc/intel_audio/"
$str_melofee_installer_04 = "rm -fr /etc/rc.modules"
$str_melofee_installer_05 = "-i <data file> Install"
$str_melofee_installer_06 = "cteate home folder failed"
$str_melofee_installer_07 = "create rootkit file failed"
$str_melofee_installer_08 = "create auto start file failed"
$str_melofee_installer_09 = "Remove Done!" // only 3 files on VT with this :D
$str_melofee_installer_10 = "Unkown option %c\n"
condition:
any of them
}
rule UNK_APT_Alien_Implant {
meta:
author = "Exatrack"
date = "2023-03-03"
update = "2023-03-03"
description = "Detects an unknown implant from AlienManager family, maybe related to melofee"
tlp = "CLEAR"
sample_hash = "3535f45bbfafda863665c41d97d894c39277dfd9af1079581d28015f76669b88,"
strings:
$str_alien_01 = "[+] Connect %s Successed,Start Transfer..."
$str_alien_02 = "Alloc buffer to decrypt data error, length == %d."
$str_alien_03 = "pel_decrypt_msg data error, error"
$str_alien_04 = "encrypt data error, length == %d."
$str_alien_05 = "DoRecvOverlapInternal error!"
$str_alien_06 = "Socks Listen port is %d,Username is %s, password is %s"
$str_alien_07 = "Start port mapping error! remoteAddr=%s remotePort=%d localAddr=%s localPort=%d"
$str_alien_08 = "OnCmdSocksStart error!"
$str_alien_09 = "The master isn't readable!"
$str_alien_10 = "ConnectBypassSocks proxy:%s:%d error!"
$str_alien_11 = "ConnectBypassSocks to %s %d"
$str_alien_12 = "now datetime: %d-%d-%d %d:%d:%d"
$str_alien_13 = "Not during working hours! Disconnect!"
$str_alien_14 = "Example: ./AlienReverse --reverse-address=192.168.1.101:80 --reverse-password=123456"
$str_alien_15 = "Not during working hours! Disconnect!"
$str_alien_16 = "SocksManager.cpp"
$str_alien_17 = "connect() in app_connect"
$str_alien_18 = "They send us %hhX %hhX"
$str_alien_19 = "your input directory is not exist!"
$str_alien_20 = "Send data to local error ==> %d.\n"
condition:
any of them
}