Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis

bsc.blockrazor.xyz

TLP:CLEAR
Active

Domain

Description

An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:01
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of bsc.blockrazor.xyz

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.