Vawtrak

Malware updated 4 months ago (2024-05-04T18:40:07.522Z)
Download STIX
Preview STIX
Vawtrak is a malicious software (malware) designed to exploit and damage computer systems. It infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, Vawtrak steals personal data, disrupts operations, and can even hold data hostage for ransom. The infection process begins when an executable file is run, which then downloads Pony and Vawtrak malware variants to steal data. H1N1, a loader malware variant, has been known to deliver Pony DLLs and Vawtrak executables to infected machines. The malware's operation involves copying itself to "%system32%" and creating a registry run key entry for persistence. Upon execution, it communicates with an attacker-controlled website to download a variant of the Pony malware, "pm.dll", along with a standard Vawtrak trojan. As Brad Duncan from the SANS Internet Storm Center warns, documents containing a malicious VB macro described as Hancitor, Chanitor, or Tordal can retrieve a Pony downloader DLL upon enabling macros. This Pony downloader then retrieves and installs the Vawtrak malware. In August, Palo Alto Networks identified a shift in the attack strategy of a Hancitor downloader variant. Instead of leveraging the latest incarnation of H1N1, it distributed the Pony and Vawtrak executables. Additionally, a custom crypter was discovered to be used for both TrickLoader and Vawtrak, as well as Pushdo and Cutwail malware. Once downloaded and executed, the malware drops an intermediate payload that further downloads a Pony DLL and Vawtrak executable, which perform data theft and connect to a command and control (C2) server.
Description last updated: 2023-09-07T13:47:57.693Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Vawtrak Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Spammers Revive Hancitor Downloader Campaigns
MITRE
2 years ago
TrickBot: We Missed you, Dyre
MITRE
2 years ago
H1N1: Technical analysis reveals new capabilities
MITRE
2 years ago
Hancitor (AKA Chanitor) observed using multiple attack approaches | Mandiant