216.73.216.6

Unmasking Prometei: A Deep Dive Into MXDR Findings

· Published 23/10/2024 17:36 · Modified 24/10/2024 10:21

Export JSON

Essential information

Published
23/10/2024 17:36
Modified
24/10/2024 10:21
Tags
2024-10-23 CVE-2019-0708 CVE-2021-26858 CVE-2021-27065 botnet credential-theft cryptocurrency mining dga lateral movement prometei tor web shell
Related entities
1 intrusion sets (apt), 20 techniques (mitre), 1 malware, 5 others

Description

This analysis examines the 's infiltration of a customer's system through a targeted brute force attack. Leveraging Trend Vision One, the investigation traced the 's detailed installation routine and stealthy tactics. , a modular malware family used for and credential theft, spreads by exploiting vulnerabilities and using PowerShell scripts. The downloads compressed archives containing various components to maintain control over infected devices. Key findings include the use of a domain generation algorithm for command and control, deployment of web shells, and connections to the network. The threat actors behind are likely Russian-speaking individuals, as evidenced by language settings and targeting behaviors.

External references