IOC Radar
TLP:WHITE12 IOCs

Raccoon Infostealer Malware Returns with New TTPS – Detection & Response

SI
Security Investigation
Published August 18, 2022Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREhttp://88.119.170.241/http://85.192.63.46/a…http://85.192.63.46/CAPABILITYRaccoonVICTIMunknown
Adversary
Infrastructure(3)
Capability(1)
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1566
1/8
Phishing
ActionDeliver malware via phishing
Raccoon malware is often delivered through phishing campaigns.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise12

TypeIndicatorConfidenceScoreFirst Seen
MD551c33c00a3823180a7b39ab838542d9d
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD5c8f9b86af75c8cb9f973683dbee27f93
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD5704cb6b7d8863165857bca2c33283fa0
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttp://88.119.170.241/
intel-blogmalwarenetwork
High
58
Jun 2, 26
MD5ecc322f22da7cee63fb2ee0bfd5df59c
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD51de2a5e94f070e9d6e8d70fe63e87175
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttp://85.192.63.46/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll
intel-blogmalwarenetwork
High
58
Jun 2, 26
MD5e490eacd7d52073891790cd3411a1221
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD52eb2d4dc60b185e1961746b120d45f97
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD57a1618c1616dae2aa4402b2f9f0febc7
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD552b4394897b2ddd3c47ec410ea1ff869
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttp://85.192.63.46/
intel-blogmalwarenetwork
High
58
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph12 total IOCs
MD5URL
MD59URL3Malware1REPORTRaccoon Infostealer MalwarRaccoon
scroll to zoom · drag to pan · click IOC to open