#ParsedReport #CompletenessHigh
10-09-2026
From a Pension-Themed Spear-Phishing Email to a GitHub-Backed Implant: Investigating a SideWinder Connection
https://www.malwareinfo.app/blog/posts/dellheuristics-winhttp-github-api-runtime-memory-analysis/
Report completeness: High
Actors/Campaigns:
Sidewinder
Southnet
Threats:
Spear-phishing_technique
Motw_bypass_technique
Victims:
Government organizations, Defence organizations, Diplomatic organizations, Government employees
Industry:
Maritime, Government
Geo:
Asia, Sri lanka, Nepal, Bangladesh, Pakistan, Myanmar, Asian
CVEs:
CVE-2017-0199 [Vulners]
CVSS V3.1: 7.8,
Vulners: Exploitation: True
Soft:
- microsoft office (2007, 2010, 2013, 2016)
- microsoft windows_7 (-)
- microsoft windows_server_2008 (-, r2)
- microsoft windows_server_2012 (-)
- microsoft windows_vista (-)
have more...
TTPs:
Tactics: 4
Technics: 9
IOCs:
IP: 1
File: 6
Hash: 3
Path: 1
Domain: 1
Url: 9
Soft:
WinHTTP, Microsoft Office, inHTTP re, Task Scheduler, Windows Security
Algorithms:
zip, sha256, base64
Functions:
WinHTTP
Win API:
EXE, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpOpenRequest, ExitProcess, WinHttpConnect, WinHttpReadData, GetLastError, WinHttpQueryHeaders
Languages:
powershell, cscript, visual_basic
Platforms:
x64
Post #32372
33