logo

APT32__2019__Funky_malware_format_found_in_Ocean_Lotus_sample.pdf

ID: 5a1964a8-26c6-400b-9fca-7a186e6a6e9e

STIX ID: report--5a1964a8-26c6-400b-9fca-7a186e6a6e9e

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-04-23

Last Modified Date: 2019-04-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This blog post presents a deep technical analysis of an Ocean Lotus (APT32) sample from 2017: a spear-phishing ZIP executable disguised as a PDF that unpacks a dropper which installs CAB and BLOB custom-formatted payloads via proprietary DLL loaders, achieves persistence (Run key and service), maps and reconstructs a reversed PE in memory, resolves imports via an atypical IAT of jump stubs, and attempts C2 communication to several domains; the report includes indicators and a parser for the custom format.