Google Ad Campaign Offers Fake Advanced IP Scanner with MadMxShell Malware
Google Ad Campaign Offers Fake Advanced IP Scanner with MadMxShell Malware#### Between November 2023 and March 2024, 45 domains were registered using typosquatting and impersonating sites such as Advanced IP Scanner, Angry IP Scanner, PRTG IP Scanner, and ManageEngine.

The advanced-ip-scanner.zip file that the attackers dropped on the fake site contains the IVIEWERS.dll file and the Advanced-ip-scanner.exe executable. Two additional files — OneDrive.exe and Secur32.dll — are extracted during installation.
OneDrive.exe is then exploited to sideload Secur32.dll and ultimately run the backdoor with shellcode, but not before persistence is set on the host using a scheduled task. It also disables Microsoft Defender antivirus.
The backdoor — named for the fact that it uses DNS MX queries to communicate with the C2 server — is designed to collect system information about the compromised system.
It sends the collected data to the C2 server in a DNS Mail Exchange (MX) packet and receives commands encoded in a reply packet.
“In addition, the backdoor uses evasion techniques such as anti-dumping to prevent memory analysis and make forensic security solutions more difficult.”
It is currently unknown where the malware operators came from and what their intentions are.