
Fake 'Jerusalem Brochure' PDF Hides Anti-Debug Spyware Dropper
A Windows dropper disguised as a conference brochure checks for sandboxes and debuggers before contacting a domain registered just weeks earlier. Persistence, WMI-based spreading, and C2 beaconing are all directly evidenced in the sample, while the phishing delivery itself is inferred from matching filenames and timestamps.
A Windows dropper built to look like a conference handout — internally named "Brochure-Jerusalem_26082019_pdf.exe" — checks whether anyone is watching it before it does anything else, and only then reaches out to a domain registered ten weeks before the sample was analyzed. The file (284a0c5c…dbd01) carries a matching PDF resource path inside it, reads the CPU clock directly to spot a sandbox, installs itself to survive a reboot, and calls out over WMI to spread to other machines on the same…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read