Skip to content

MALICIOUS (1) campaign cataloged at 2024-10-03(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2024-10-pyutiltool

When importing the module and a specific file exists in the current directory, obfuscated code downloads and starts the next stage of obfuscated code (cstealer infostealer)

Abuse categories

infostealer

Campaign uses infostealer.

infostealer:cstealer

Campaign uses infostealer:cstealer.

obfuscation

Campaign uses obfuscation.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • blockatlaspro.com

  • hxxps://blockatlaspro.com/application.py

  • hxxps://blockatlaspro.com/test.py

Packages in the campaign

campaign:2024-10-pyutiltool