Malware is served under domain f3322.org which is having a super bad reputation in being used by Mr.Black ELF attacks and many more ELF attacks.The PE is a Win32/Zegost variant, the dropper/backdoor type. It drops, self deleted, auto-start set in registry, starting service. So it looks like that their services is used by the malware activities. It means the actor can be traced via contacting the f3322.org abuse accordingly. We're on it for we have long list of malicious subdomains used now.
Created: 2026-02-23
Indicatorsは見つかっていない。
このPulseに見つかったCVEはありません。