Post

Log inSign up

Post

Log inSign up

Sudeep_Singh on X: "Dropping Elephant targets East Asia using ICASSE decoy theme. LNK MD5: a02dca4d1487f9141a90f3b11aa08d64 Malicious DLL: f8f03a6a3edbf7985469de26bdfb5e97 Base64-encoded and XOR-encrypted shellcode: fdfce91c0a9758a24ea98b48c44fdc9c .NET assembly payload: 1ac87c87bc585605b75b269ca510fc52 Malicious DLL - msdtctm.dll sideloaded by msdtc.exe Scheduled task name - GoogleErrorReport launches msdtc.exe to start attack chain DLL sideloading -> Base64 + XOR decrypt shellcode -> Donut shellcode -> in-memory execution of .NET DLL All DLL sideloading components downloaded from the staging domain: cas-edu[.]org C2 URL: hxxps://wtechnote[.]org/c019e2b6b055-48d2/a5c5a153b6caddd7.php #threatintel @smica83 @malwrhunterteam @volrant136"

@SinghSoodeep
Sudeep_Singh
@SinghSoodeep
Dropping Elephant targets East Asia using ICASSE decoy theme. LNK MD5: a02dca4d1487f9141a90f3b11aa08d64 Malicious DLL: f8f03a6a3edbf7985469de26bdfb5e97 Base64-encoded and XOR-encrypted shellcode: fdfce91c0a9758a24ea98b48c44fdc9c .NET assembly payload: 1ac87c87bc585605b75b269ca510fc52 Malicious DLL - msdtctm.dll sideloaded by msdtc.exe Scheduled task name - GoogleErrorReport launches msdtc.exe to start attack chain DLL sideloading -> Base64 + XOR decrypt shellcode -> Donut shellcode -> in-memory execution of .NET DLL All DLL sideloading components downloaded from the staging domain: cas-edu[.]org C2 URL: hxxps://wtechnote[.]org/c019e2b6b055-48d2/a5c5a153b6caddd7.php #threatintel @smica83 @malwrhunterteam @volrant136
10:10 AM · Aug 3, 2026·
5,847
Views
1

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email

Relevant people

Avatar
Sudeep_Singh@SinghSoodeepFollow

Trending now

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @SinghSoodeep
    Sudeep_Singh
    @SinghSoodeep
    Dropping Elephant targets East Asia using ICASSE decoy theme. LNK MD5: a02dca4d1487f9141a90f3b11aa08d64 Malicious DLL: f8f03a6a3edbf7985469de26bdfb5e97 Base64-encoded and XOR-encrypted shellcode: fdfce91c0a9758a24ea98b48c44fdc9c .NET assembly payload: 1ac87c87bc585605b75b269ca510fc52 Malicious DLL - msdtctm.dll sideloaded by msdtc.exe Scheduled task name - GoogleErrorReport launches msdtc.exe to start attack chain DLL sideloading -> Base64 + XOR decrypt shellcode -> Donut shellcode -> in-memory execution of .NET DLL All DLL sideloading components downloaded from the staging domain: cas-edu[.]org C2 URL: hxxps://wtechnote[.]org/c019e2b6b055-48d2/a5c5a153b6caddd7.php #threatintel @smica83 @malwrhunterteam @volrant136
    10:10 AM · Aug 3, 2026·
    5,847
    Views
    1