The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
AI Summary
Aeternum is a recently discovered C++ botnet loader that uses the Polygon blockchain for decentralized command-and-control (C2) operations. The malware retrieves encrypted or plaintext instructions from smart contracts on the blockchain by querying public RPC endpoints, enabling resilient and low-cost infrastructure resistant to takedowns. Three distinct malware samples were analyzed: the initial Aeternum loader, a Python-based downloader, and a multi-component payload combining XWorm RAT, XMRig cryptocurrency miner, and data exfiltration tools. The threat leverages Telegram APIs and GitHub repositories for secondary C2 and payload delivery, while using weak encryption schemes that allow decryption via contract address and payload analysis.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 28 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898 | Details → |
| SHA-256 | 1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505 | Details → |
| Filename | DotNetZip.dll | Details → |
| Filename | putty.exe | Details → |
| Filename | Wmi_Framework_APIKEY_wmsnet_<random_value>.lnk | Details → |
| Filename | wmiframework.exe | Details → |
| Filename | ZrvEsJQzWQ.exe | Details → |
| Filename | STAAAAAS.exe | Details → |
| Domain | api[.]telegram[.]org | Details → |
| GitHub Repo | lencod | Details → |
| GitHub Repo | Mash3Do | Details → |
| Registry User | lencod | Details → |
| Registry User | Mash3Do | Details → |
| SHA-256 | f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27 | Details → |
| SHA-256 | 4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f | Details → |
| SHA-256 | 81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f | Details → |
| Domain | gulf[.]moneroocean[.]stream | Details → |
| IP | 193[.]221[.]200[.]219 | Details → |
| Domain | sekirolegion[.]duckdns[.]org | Details → |
| SHA-256 | ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2 | Details → |
| Domain | download[.]sftp-api-group-wechat[.]com | Details → |
| Domain | update[.]constant-path[.]xyz | Details → |
| Domain | update-launcher[.]xyz | Details → |
| Domain | test-steve[.]cyou | Details → |
| Filename | PythonLauncher-*.lnk | Details → |
| Filename | dpapimig.exe | Details → |
| Filename | WmiPrvSE.exe | Details → |
| Domain | cdnjsdelivr[.]beer | Details → |