Malware
LIGHTRAIL
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
Indicators of Compromise 35
Domain aecert[.]org Domain buisness-centeral-transportation[.]com Domain business-deegital[.]azurewebsites[.]net Domain business-deegital[.]com Domain business-startup[.]azurewebsites[.]net Domain businessdeegital[.]azurewebsites[.]net Domain businessmixture[.]com Domain businessstartup[.]azurewebsites[.]net Domain global-reds[.]com Domain healthcarezoom-centeral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]org Domain maadinglobal[.]com Domain neexportfolio[.]azurewebsites[.]net Domain neexportfolio[.]com Domain realhealthshop[.]com Domain smartconnect[.]azurewebsites[.]net Domain thehealth-life[.]com Domain tjconsultingservices[.]com Domain toadreport[.]azurewebsites[.]net Filename IPHLPAPI.dll Filename libwinpthread-1.dll Filename sspicli.dll Filename unbcl.dll MD5 42f847597109da2a220391bb09d00676 MD5 5fa15ef96808ea82f0a6176f0bb4b386 MD5 6038d42af0affd1fb263f470c0956f6b MD5 a239e655709a2518dd0b7bdbed163679 MD5 ae628efa305387b633dce82f9364875b MD5 afb1c1583606599c7272cfb33cc6f498 MD5 c832ecd135781b11f59e3fffb3d2b6ac MD5 c90f0efadbf322e5eb1c4103a38c30e6 MD5 d09b14a2fe01c7363ecc56f5d046162c MD5 f7d36cc5904a53252d2bb3d21615134f IP 172[.]86[.]98[.]113
MITRE ATT&CK TTPs 9
T1001.002 T1027 T1059.001 T1071 T1071.001 T1090 T1105 T1133 T1574.002
Steganography
Command And Control
Obfuscated Files or Information
Defense Evasion
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
External Remote Services
Persistence
DLL Side-Loading
Persistence