General

  • Target

    https://cheat.laminadora.cl

  • Sample

    240627-23s2mszblj

Malware Config

Targets

    • Target

      https://cheat.laminadora.cl

    • Rhadamanthys

      Rhadamanthys is an info stealer written in C++ first seen in August 2022.

    • Suspicious use of NtCreateUserProcessOtherParentProcess

    • Command and Scripting Interpreter: PowerShell

      Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.

    • Executes dropped EXE

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Discovery

System Information Discovery

2
T1082

Query Registry

2
T1012

Remote System Discovery

1
T1018

Tasks