Skip to content

Hide Navigation Hide TOC

Matanbuchus (2214b113-6942-494f-94b7-576e74fccdb5)

Matanbuchus is a loader promoted by BelialDemon. It can launch an EXE or DLL file in memory, leverage schtasks.exe to add or modify task schedules, and launch custom PowerShell commands, among other capabilities. Attackers use a Microsoft Excel document as the initial vector to drop the Matanbuchus Loader DLL.

Cluster A Galaxy A Cluster B Galaxy B Level
Matanbuchus (e30f2243-9e69-4b09-97ab-1643929b97ad) Malpedia Matanbuchus (2214b113-6942-494f-94b7-576e74fccdb5) Tool 1