Campaigns
Glupteba: The Blockchain-Enabled Modular Malware

Glupteba: The Blockchain-Enabled Modular Malware

GluptebaBlockchain
Glupteba is a complex and advanced form of malware that has been affecting Windows devices globally since 2019. It utilizes blockchain technology and has multiple modules that can be used for various malicious activities,

Indicators of Compromise

trumops.com
getfixed.xyz
limeprime.org
mordo.ru
leappoach.info
7owe32rodnp3vnx2ekqncoegxolkmb3m2fex5zu6i2bg7ktivhwvczqd.onion
all-smart-green.com
cdneurops.shop
tyturu.com
nahbleiben.at
checkpos.net
duniadekho.bar
www.sxhxrj.com
spaldingcompanies.com
herscan.io
anuanage.info
dg2sz7pxs7llf2t25fsbutlvvrjij4pmojugn75cmxnvoshmju6dzcad.onion
nameiusr.com
getyourgift.life
dll1.stdcdn.com
privacy-tools-for-you-791.com
egsagl.com
cdneurops.buzz
gc-distribution.biz
i.xyzgamei.com
reosio.com
newcc.com
papmcl4r32awafck75y5446n252qqqq4h6c4y2slaayposrtfbcebdqd.onion
source3.boys4dayz.com
sxx.leappoach.info
zaoshanghaoz.net
cdneurops.health
retoti.com
real-enter-solutions.xyz
revouninstaller.homes
younghil.com
bestony.info
x4l2doee6uhhf3lqjvjodgqtxsjvwbkdqyldhwyhwkhf4y23aqq7jayd.onion
topexpertshop.com
ads-memory.biz
piratia-life.ru
limeprime.com
godespra.com
noblecreativeaz.com
mastiakele.xyz
mydomelem.com
enter-me.xyz
yturu.com
greenphoenix.xyz
ciskotik.com
onlinehueplet.com
maesvpovrwqfaqjw44bbeb2w62h6n7eyosbeit7rfrrdbyjymqaxfryd.onion
am1420wbec.com
routers.rip
zaoshang.ooo
ginta.link
host-data-coin-11.com
signaturebusinesspark.com
flexnetinformatica.com.br
cdneurops.pics
azilominehostz.xyz
fennsports.com
dafflash.com
yeug3c6mnwocixwlotka4nwo3fjtfic65o4psmpxvrdul5q7dgjmsvad.onion
zaoshang.moscow
filimaik.com
r5vg4h5rlwmo6oa3p3vlckuvf5na2wb2tnqbsbkivhrhlyze6czlpjad.onion
presstheme.me
v.xyzgamev.com
cdneurop.cloud
3ebu257qh2dlauxqj7cgv3i55e4orb55mwgqf4tq7eicsa3dfhr4aaid.onion
tmetres.com
mastiakele.icu
file-coin-host-12.com
toa.mygametoa.com
iceanedy.com
nisdably.com
connectini.net
evocterm.com
tg8.cllgxx.com
islamic-city.com
careerguide4u.online
motinkon.co
bihgkrr546ctjdn4mwr7x4bhvwz55sftx6xir6cwlfo6rhppd2eu7syd.onion
buy-fantasy-fo0tball.com.sg
mastiakele.cyou
stylesheet.faseaegasdfase.com
hhiuew33.com
one-wedding-film.com
runmodes.com
patchlinks.com
c43tnmrkzfmkjyd3j4v6xbyrd67q6pskzy67dwkzj36uoqwpoju2loyd.onion
privacy-tools-for-you-782.com
2pkktxkf3gnpcjh2bhi62arz2ieyjgxocb3jne3kc2nu2yvyxqq23nad.onion
strtz.site
eurekabike.com
all-mobile-pa1ments.com.mx
zaoshanghao.su
buy-fantasy-gmes.com.sg
dollybuster.at
appwebstat.biz
banhamm.com
topniemannpicksh0p.cc
zaoshang.ru
cdntokiog.studio
reoseio.com
whsddzs.com
jackytpload.su
remik-franchise.ru

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

The following steps can be taken to remediate a Glupteba infection:

  • Isolate the infected device: Disconnect the infected device from the internet and any other networks to prevent the malware from spreading.

  • Run a malware scan: Use a reputable antivirus or anti-malware software to scan the infected device for Glupteba and other forms of malware.

  • Remove the malware: Follow the instructions provided by the antivirus or anti-malware software to remove the Glupteba malware from the infected device.

  • Update software: Make sure to update the operating system and any installed software to the latest version to address vulnerabilities that may have been exploited by the malware.

  • Change passwords: If the infected device contained sensitive information, such as login credentials or financial information, change the passwords for any relevant accounts as a precaution.

  • Monitor for further infection: Continue to monitor the infected device for any signs of further infection, and take additional steps as needed to remove any additional malware that may have been installed.

  • Implement best practices: To reduce the risk of future infections, implement best practices such as using reputable security software, practicing safe browsing habits, enabling firewalls, and using strong and unique passwords.

Reports & References2

Observed Countries250

AD (792)
AE (683)
AF (916)
AG (957)
AI (469)
AL (121)
AM (299)
AO (256)
AQ (743)
AR (594)
AS (434)
AT (717)
AU (558)
AW (184)
AX (655)
AZ (403)
BA (469)
BB (607)
BD (685)
BE (745)
BF (903)
BG (547)
BH (991)
BI (237)
BJ (380)
BL (148)
BM (400)
BN (481)
BO (604)
BQ (672)
BR (471)
BS (372)
BT (400)
BV (648)
BW (585)
BY (596)
BZ (332)
CA (79)
CC (922)
CD (202)
CF (531)
CG (865)
CH (957)
CI (755)
CK (704)
CL (340)
CM (932)
CN (92)
CO (363)
CR (386)
CU (237)
CV (473)
CW (501)
CX (834)
CY (176)
CZ (922)
DE (475)
DJ (510)
DK (376)
DM (472)
DO (546)
DZ (386)
EC (183)
EE (383)
EG (254)
EH (563)
ER (585)
ES (657)
ET (491)
FI (565)
FJ (377)
FK (139)
FM (228)
FO (194)
FR (105)
GA (365)
GB (918)
GD (435)
GE (876)
GF (219)
GG (800)
GH (458)
GI (957)
GL (255)
GM (328)
GN (193)
GP (982)
GQ (799)
GR (135)
GS (999)
GT (999)
GU (103)
GW (572)
GY (459)
HK (463)
HM (69)
HN (846)
HR (362)
HT (193)
HU (119)
ID (734)
IE (626)
IL (752)
IM (292)
IN (55)
IO (471)
IQ (264)
IR (244)
IS (345)
IT (79)
JE (809)
JM (295)
JO (771)
JP (985)
KE (864)
KG (146)
KH (321)
KI (56)
KM (312)
KN (748)
KP (945)
KR (382)
KW (149)
KY (657)
KZ (60)
LA (846)
LB (51)
LC (651)
LI (62)
LK (86)
LR (699)
LS (765)
LT (509)
LU (227)
LV (286)
LY (157)
MA (937)
MC (224)
MD (26)
ME (814)
MF (855)
MG (285)
MH (971)
MK (87)
ML (450)
MM (683)
MN (598)
MO (117)
MP (40)
MQ (810)
MR (354)
MS (541)
MT (883)
MU (323)
MV (701)
MW (508)
MX (162)
MY (294)
MZ (365)
NA (927)
NC (338)
NE (723)
NF (203)
NG (815)
NI (199)
NL (146)
NO (253)
NP (303)
NR (577)
NU (610)
NZ (139)
OM (898)
PA (827)
PE (749)
PF (126)
PG (954)
PH (578)
PK (607)
PL (217)
PM (699)
PN (833)
PR (662)
PS (445)
PT (337)
PW (706)
PY (580)
QA (456)
RE (756)
RO (911)
RS (368)
RU (162)
RW (845)
SA (16)
SB (793)
SC (749)
SD (821)
SE (765)
SG (665)
SH (639)
SI (250)
SJ (947)
SK (120)
SL (347)
SM (398)
SN (138)
SO (272)
SR (237)
SS (881)
ST (718)
SV (247)
SX (252)
SY (575)
SZ (586)
TC (199)
TD (92)
TF (655)
TG (31)
TH (105)
TJ (47)
TK (286)
TL (423)
TM (908)
TN (906)
TO (896)
TR (485)
TT (433)
TV (173)
TW (606)
TZ (881)
UA (135)
UG (736)
UM (911)
US (864)
UY (797)
UZ (329)
VA (95)
VC (859)
VE (979)
VG (635)
VI (130)
VN (157)
VU (411)
WF (392)
WS (476)
XK (507)
YE (665)
YT (45)
ZA (513)
ZM (280)
ZW (553)