DragonOK__2017__Deep_Dive_on_the_DragonOK_Rambo_Backdoor_Morphick_Cyber_Security.pdf
ID: fed9a192-4547-472e-a907-da4c6fdf7622
STIX ID: report--fed9a192-4547-472e-a907-da4c6fdf7622
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2017-02-28
Last Modified Date: 2017-02-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This blog post provides a deep technical analysis of the DragonOK 'Rambo' backdoor and its multi-stage dropper: a malicious RTF that decodes and drops HeartDll.dll, vprintproxy.exe (legitimate VMware binary used for DLL sideloading), and vmwarebase.dll which implements the backdoor. The report covers evasion techniques (busy-loop mallocs, stack-built strings), configuration extraction (TEA-decrypted offsets), persistence via a Run key, C2 details (busserh.mancely.com, 108.61.117.31), host reconnaissance and exfiltration behavior, download-and-execute capability, and provides multiple IOCs and sample hashes.
