Malware News AdvisorsBot Downloader Emerges in Raft of Malware Campaigns

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,396
A new downloader was disclosed today, sporting significant anti-analysis features and increasingly sophisticated distribution techniques.

Researchers at Proofpoint have been tracking the downloader as a first-stage payload in campaigns since May 2018. Dubbed AdvisorsBot (due to early command-and-control domains, all containing the word “advisors”), it has been targeting hotels, restaurants and telecom-sector victims.
“A majority of the targets were located in the United States, but we’ve observed this threat globally,” Chris Dawson, threat intelligence lead at Proofpoint, told Threatpost. “To date, the campaigns have targeted thousands of recipients.”

The research team said in a post Thursday that the campaigns use several themes in their email lures, including a “grievance” gambit.
 

Libera Milanesi

Level 2
Verified
Aug 19, 2018
52

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,396

Libera Milanesi

Level 2
Verified
Aug 19, 2018
52
Thanks for sharing and letting me know, I hadn't seen that one yet. ProofPoint have a new fan, I like how they remember to include the IOCs, it's really helpful.

Marap downloader (PDF version):
Antivirus scan for 2c5729e17b64cd4e905ccfeabbc913ed945e17625c35ec1d6932194aae83d7c6 at 2018-08-23 23:54:05 UTC - VirusTotal
Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'DOC_2606660638_10082018.pdf'

Marap payload:
Antivirus scan for bc1fc69f9747dc034ece7d9bb795c5e596d9be6ca71efe75c6c0fd18f3cbfbf5 at 2018-08-24 00:08:29 UTC - VirusTotal
Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'data3.exe'

(Credits to the ProofPoint article (linked to by @silversurfer in the above post) containing the IOCs).

If anybody needs the downloads from the sources linked to above and cannot download it from there for one reason or another, feel free to let me know and I can help you out.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top