/
    Zpět na blog
    Security

    Google Ad Campaign Offers Fake Advanced IP Scanner with MadMxShell Malware


    Google Ad Campaign Offers Fake Advanced IP Scanner with MadMxShell Malware#### Between November 2023 and March 2024, 45 domains were registered using typosquatting and impersonating sites such as Advanced IP Scanner, Angry IP Scanner, PRTG IP Scanner, and ManageEngine.

    image

    The advanced-ip-scanner.zip file that the attackers dropped on the fake site contains the IVIEWERS.dll file and the Advanced-ip-scanner.exe executable. Two additional files — OneDrive.exe and Secur32.dll — are extracted during installation.

    OneDrive.exe is then exploited to sideload Secur32.dll and ultimately run the backdoor with shellcode, but not before persistence is set on the host using a scheduled task. It also disables Microsoft Defender antivirus.

    The backdoor — named for the fact that it uses DNS MX queries to communicate with the C2 server — is designed to collect system information about the compromised system.

    It sends the collected data to the C2 server in a DNS Mail Exchange (MX) packet and receives commands encoded in a reply packet.

    “In addition, the backdoor uses evasion techniques such as anti-dumping to prevent memory analysis and make forensic security solutions more difficult.”

    It is currently unknown where the malware operators came from and what their intentions are.

    © 2026 Patrik Žák. Všechna práva vyhrazena.