logo

DragonOK__2017__Deep_Dive_on_the_DragonOK_Rambo_Backdoor_Morphick_Cyber_Security.pdf

ID: fed9a192-4547-472e-a907-da4c6fdf7622

STIX ID: report--fed9a192-4547-472e-a907-da4c6fdf7622

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2017-02-28

Last Modified Date: 2017-02-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This blog post provides a deep technical analysis of the DragonOK 'Rambo' backdoor and its multi-stage dropper: a malicious RTF that decodes and drops HeartDll.dll, vprintproxy.exe (legitimate VMware binary used for DLL sideloading), and vmwarebase.dll which implements the backdoor. The report covers evasion techniques (busy-loop mallocs, stack-built strings), configuration extraction (TEA-decrypted offsets), persistence via a Run key, C2 details (busserh.mancely.com, 108.61.117.31), host reconnaissance and exfiltration behavior, download-and-execute capability, and provides multiple IOCs and sample hashes.