python33.dll

Malware updated 4 months ago (2024-05-04T16:56:20.196Z)
Download STIX
Preview STIX
Python33.dll is a harmful malware that can infiltrate your system through various channels, including suspicious downloads, emails, or websites. Once inside, it can steal personal information, disrupt operations, or even hold your data hostage for ransom. This malicious software has been observed being uploaded to webshells, where it's sideloaded alongside other files such as inicore_v2.3.30.dll and CreateTsMediaAdm.dll, both of which have been linked to previous attacks by Emissary Panda, a cyber espionage group. A code comparison between the PYTHON33.dll and the inicore_v2.3.30.dll file, which was sideloaded in previous Emissary Panda attacks, indicates significant similarities. The same applies when comparing PYTHON33.dll and CreateTsMediaAdm.dll. In particular, Figure 9 shows a code comparison between PYTHON33.dll (right) and inicore_v2.3.30.dll (left), with the latter having been sideloaded to run the SysUpdate tool in an earlier Emissary Panda campaign. Further analysis reveals that both PYTHON33.dll and CreateTsMediaAdm.dll employ an eight-byte XOR key to decrypt a piece of shikata_ga_nai obfuscated shellcode, as demonstrated in the code diff in Figure 8. A binary comparison between PYTHON33.dll and CreateTsMediaAdm.dll libraries yields a striking similarity score of 97% with a 99% confidence level. This high degree of resemblance suggests a shared origin or purpose, underscoring the persistent threat posed by this sophisticated malware.
Description last updated: 2023-09-07T17:01:22.731Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the python33.dll Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Emissary Panda Attacks Middle East Government SharePoint Servers