The Nightmare of Global Cryptocurrency Companies DangerousPassword of the APT Organization.pdf
ID: f1ef5aa5-8706-491b-a947-8e9297792725
STIX ID: report--f1ef5aa5-8706-491b-a947-8e9297792725
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2020-03-19
Last Modified Date: 2020-03-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatBook details the "DangerousPassword" APT campaign targeting cryptocurrency companies: attackers distribute ZIP attachments containing encrypted decoy documents and LNK shortcuts (e.g., Password.txt.lnk) that call mshta to retrieve obfuscated VBScript payloads from shortlinks/C2. The VBScript backdoor performs AV/host checks, drops/executes persistent startup shortcuts, collects host and process data, and issues POST/GET to C2 servers (example IP 41.85.145.164:8080 and domains like showprice.xyz, start.showprice.xyz, drivegoogle.publicvm.com); server-side artifacts include remote management tooling (TightVNC). The report includes file/sample hashes, code excerpts, network captures, and correlated malicious domains and shortlinks, indicating a resourceful, long-running targeted campaign (active since at least March 2018).
