logo

NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 650e4606-a20c-40c9-95ee-707e37abe3bd

STIX ID: report--650e4606-a20c-40c9-95ee-707e37abe3bd

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2016-08-11

Last Modified Date: 2016-08-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzed a December 2015 spear-phishing attack against an Uzbek diplomat that used a malicious Word document (exploiting CVE-2012-0158) to drop a SFX RAR payload which leverages DLL side-loading to install a NetTraveler DLL. The report details the infection chain, decrypted configuration extraction, runtime behavior (mutex, service enumeration), C2 infrastructure (voennovosti.com -> 98.126.38.107), and provides SHA256 indicators for the malicious components.