QUILTED_TIGER__2019__Malware_analysis_about_sample_of_APT_Patchwork.pdf
ID: 7ea512b8-b2a0-4185-b796-c6745aef58b1
STIX ID: report--7ea512b8-b2a0-4185-b796-c6745aef58b1
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2019-09-11
Last Modified Date: 2019-09-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report presents a technical analysis of an APT (Patchwork) campaign leveraging an InPage INP exploit (CVE-2017-12824) to deliver a two-stage Windows payload that extracts to temp, establishes persistence via RunOnce, performs anti-debug and anti-analysis checks, and uses process hollowing to load a C2-connected loader; the report includes IOCs (file hashes, domain, IP), MITRE ATT&CK mappings, and contextual targeting information suggesting ties to Pakistan-related lures.
