Cmstar Downloader: Lurid and Enfal's New Cousin - Palo Alto Networks BlogPalo Alto Networks Blog
ID: fa61e510-5502-4a75-be83-cba7ccca1fb0
STIX ID: report--fa61e510-5502-4a75-be83-cba7ccca1fb0
Threat Score
70/100
Uploaded: 2026-08-07
Published Date: 2015-05-29
Last Modified Date: 2015-05-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 presents a technical analysis of the Cmstar downloader used in spear-phishing campaigns, describing an unusual method for manually building the Import Address Table via character/offset mappings, a hashing routine to detect AV processes (notably Kaspersky's avp.exe), encrypted configuration and shellcode that communicates with multiple C2 domains, registry persistence artifacts, and substantial infrastructure overlap tying Cmstar to Lurid/Enfal and Cmwhite; the report includes numerous IOCs (filenames, hashes, domains), delivery document metadata (MNKit and Tran Duy Linh toolkits), and a Yara rule for detection.
