Summary:
A recent discovery by researcher specialists unveiled a malicious file named "Application to Consulate General.doc." This document is identified as distributing the Jaca framework, employing a scheme similar to previous attacks. Notably, the Jaca sample within the file contains a DLL named "NewRegdlTest.dll," with exports including "DllCanUnLoadNow" and "DllUnregisterServer," alongside a mutex labeled "08808." Additionally, a scheduled task titled "pre-staged app cleanup" is set to run from the directory %TEMP%\CommonFiles, utilizing "mscorlib.dll" and "DllCanUnLoadNow." Further investigation revealed that the C2 domain associated with this malicious activity is "trigershop[.]info."[/subscribe_to_unlock_form]
Summary:
A recent discovery by researcher specialists unveiled a malicious file named "Application to Consulate General.doc." This document is identified as distributing the Jaca framework, employing a scheme similar to previous attacks. Notably, the Jaca sample within the file contains a DLL named "NewRegdlTest.dll," with exports including "DllCanUnLoadNow" and "DllUnregisterServer," alongside a mutex labeled "08808." Additionally, a scheduled task titled "pre-staged app cleanup" is set to run from the directory %TEMP%\CommonFiles, utilizing "mscorlib.dll" and "DllCanUnLoadNow." Further investigation revealed that the C2 domain associated with this malicious activity is "trigershop[.]info."[emaillocker id="1283"]
Threat Profile:

References:
Eventus Security Threat Research & Development Team
[/emaillocker]