BelialDemon__2024__TLP-CLEAR-Matanbuchus-Co-Code-Emulation-and-Cybercrime-Infrastructure-Discovery-1.pdf
ID: c9e692a4-16f2-4b2f-be35-b80c5b58bdc8
STIX ID: report--c9e692a4-16f2-4b2f-be35-b80c5b58bdc8
Threat Score
72/100
Uploaded: 2026-08-14
Published Date: 2024-04-30
Last Modified Date: 2024-04-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents active malspam and Google Ads campaigns distributing the Matanbuchus loader and SocGholish redirectors, provides detailed static and dynamic code analysis (string decryption via emulation, API hashing, anti-debug techniques), maps C2/infrastructure hosted on apparent Russian bulletproof autonomous systems (AS198953, AS57523, AS216234), links activity to criminal affiliates (TA577 / Black Basta) and provides IOCs and detection recommendations to anticipate and mitigate further campaigns.
