APT32__2019__Funky_malware_format_found_in_Ocean_Lotus_sample.pdf
ID: 5a1964a8-26c6-400b-9fca-7a186e6a6e9e
STIX ID: report--5a1964a8-26c6-400b-9fca-7a186e6a6e9e
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-04-23
Last Modified Date: 2019-04-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This blog post presents a deep technical analysis of an Ocean Lotus (APT32) sample from 2017: a spear-phishing ZIP executable disguised as a PDF that unpacks a dropper which installs CAB and BLOB custom-formatted payloads via proprietary DLL loaders, achieves persistence (Run key and service), maps and reconstructs a reversed PE in memory, resolves imports via an atypical IAT of jump stubs, and attempts C2 communication to several domains; the report includes indicators and a parser for the custom format.
