A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #32849  by r0ny
 Wed Apr 24, 2019 1:34 pm
DNSpionage brings out the Karkoff

ref:https://blog.talosintelligence.com/2019 ... rkoff.html

IOCs:
b017b9fc2484ce0a5629ff1fed15bca9f62f942eafbb74da6a40f40337187b04
6a251ed6a2c6a0a2be11f2a945ec68c814d27e2b6ef445f4b2c7a779620baa11
cd4b9d0f2d1c0468750855f0ed352c1ed6d4f512d66e0e44ce308688235295b5
5b102bf4d997688268bab45336cead7cdf188eb0d6355764e53b4f62e1cdf30c