Concrete signature match: TrojanDropper for 32-bit Windows platform, family Dapato
This is a concrete detection of TrojanDropper:Win32/Dapato!pz, a malicious program designed to download and execute additional payloads. It establishes persistence, communicates with remote servers (potentially AWS), and leverages techniques like code hooking and MSHTA for execution and evasion, with indications of potential integration with or impersonation of remote access software like AnyDesk.
Relevant strings associated with this threat: - set_UseShellExecute (PEHSTR_EXT) - downexecute (PEHSTR_EXT) - For i = 1 To LenB( OBH.ResponseBody ) (PEHSTR_EXT) - \vxs32.exe (PEHSTR_EXT) - https:// (PEHSTR_EXT) - .amazonaws.com/ (PEHSTR_EXT) - /vxs32.exe (PEHSTR_EXT) - \Software\Microsoft\Windows\CurrentVersion\Policies\System (PEHSTR_EXT) - ServiceApp.exe (PEHSTR_EXT) - Software\Microsoft\Windows\CurrentVersion\Run (PEHSTR_EXT) - BouncyCastle.Crypto (PEHSTR_EXT) - Org.BouncyCastle.Bcpg.OpenPgp (PEHSTR_EXT) - source\repos\AnyDeskAdd.exe\AnyDeskAdd.exe\obj\Debug\AnyDeskAdd.exe.pdb (PEHSTR_EXT) - /public/pages/Exodus.html (PEHSTR_EXT) - \WallpaperX.pdb (PEHSTR_EXT) - config.txt (PEHSTR_EXT) - log.txt (PEHSTR_EXT) - Knocker.Properties.Resources (PEHSTR_EXT) - knksvc.exe (PEHSTR_EXT) - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
3f790d1fc0bae05463f75c5c2fda33b7616230a361630da56e87f7cf26e5fd89c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa359238139e5a1bb3b057fa6bf3e2aa2961763cb48bef578648e754c1cf52da7ddd2a2d8c885e69942529c7f73a2e42f39fcc0008ff8fa80f27028427478d4147140e195f859e01fbf57168925f33a9ef2302d1cd9b33812a1ea62a20de1ea024b640da2Immediately isolate affected systems and perform a comprehensive scan with up-to-date antivirus definitions to remove all malicious components. Investigate persistence mechanisms (e.g., Run keys, services) and network logs for indicators of compromise or C2 communication, restoring from a clean backup if necessary.