MALICIOUS (1) campaign cataloged at 2024-10-03(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2024-10-pyutiltool¶
When importing the module and a specific file exists in the current directory, obfuscated code downloads and starts the next stage of obfuscated code (cstealer infostealer)
Abuse categories¶
infostealer
Campaign uses infostealer.
infostealer:cstealer
Campaign uses infostealer:cstealer.
obfuscation
Campaign uses obfuscation.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
blockatlaspro.com
-
hxxps://blockatlaspro.com/application.py
-
hxxps://blockatlaspro.com/test.py