Dropping Elephant targets East Asia using ICASSE decoy theme.
LNK MD5: a02dca4d1487f9141a90f3b11aa08d64
Malicious DLL: f8f03a6a3edbf7985469de26bdfb5e97
Base64-encoded and XOR-encrypted shellcode: fdfce91c0a9758a24ea98b48c44fdc9c
.NET assembly payload: 1ac87c87bc585605b75b269ca510fc52
Malicious DLL - msdtctm.dll sideloaded by msdtc.exe
Scheduled task name - GoogleErrorReport launches msdtc.exe to start attack chain
DLL sideloading -> Base64 + XOR decrypt shellcode -> Donut shellcode -> in-memory execution of .NET DLL
All DLL sideloading components downloaded from the staging domain: cas-edu[.]org
C2 URL: hxxps://wtechnote[.]org/c019e2b6b055-48d2/a5c5a153b6caddd7.php
#threatintel
@smica83 @malwrhunterteam @volrant136
