Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis
An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives.
· unknown severity · unattributed attribution
Evidence and provenance
- Original source
- AlienVault OTX report ↗
- Published
- 2026-07-16T05:08:43.447000Z
- Confidence basis
- No actor match
- Record ID
0fb4bb9543e4842c65ba
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.