logo

QUILTED_TIGER__2019__Malware_analysis_about_sample_of_APT_Patchwork.pdf

ID: 7ea512b8-b2a0-4185-b796-c6745aef58b1

STIX ID: report--7ea512b8-b2a0-4185-b796-c6745aef58b1

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2019-09-11

Last Modified Date: 2019-09-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report presents a technical analysis of an APT (Patchwork) campaign leveraging an InPage INP exploit (CVE-2017-12824) to deliver a two-stage Windows payload that extracts to temp, establishes persistence via RunOnce, performs anti-debug and anti-analysis checks, and uses process hollowing to load a C2-connected loader; the report includes IOCs (file hashes, domain, IP), MITRE ATT&CK mappings, and contextual targeting information suggesting ties to Pakistan-related lures.