Possible Pakistan-Linked Backdoor Targets Afghanistan

Summary
Analysis details a backdoor delivered through DLL side-loading, with Afghan government targeting clues, persistence via a Windows Run key, and C2 at 185.235.137[.]35:9000.
Key points
- A ZIP uploaded to VirusTotal from Afghanistan contained a renamed legitimate Windows executable and malicious dgxi.dll, which the executable side-loads.
- The malware copies itself and the executable to %AppData%\Microsoft\ApplicationHost\ and persists through the current user's Windows Run key.
- Its decoy PDF is in Pashto and contains names, job titles, salaries, departments, and phone numbers, suggesting a government-related lure.
- The backdoor connects to 185.235.137[.]35:9000 and sends a beacon with the victim machine's ID, name, and Windows version.
- Supported commands include file listing, upload and download, file deletion, process execution and control, and an interactive command shell.
- It uses debugger and analysis-tool checks, timing and integrity checks, and XOR-encrypted C2 configuration.
- The article provides these indicators: C2 185.235.137[.]35:9000, dgxi.dll SHA-256 a6ceacac670b88e8a8ec9ff5da6a77d9f1c896d6479b2dadb700474a8c408f80, and a ZIP hash listed in the source.
Article Details
- Attack Vectors
- A ZIP file uploaded from Afghanistan contained a legitimate Windows executable renamed to resemble recruitment information and a malicious dgxi.dll that the executable side-loads. The filename and upload origin suggest, but do not confirm, targeting of an Afghanistan government agency.
- The backdoor copies the executable and DLL to %AppData%\Microsoft\ApplicationHost\ and establishes persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
- The DLL checks for debuggers and analysis tools, decrypts its C2 configuration, and connects to the C2. Its commands support system profiling, file transfer, process execution, and an interactive shell.
- Defensive Notes
- The DLL checks for CheckRemoteDebuggerPresent(), OutputDebugStringA() timing, and the presence of named analysis tools.
- The C2 configuration is XOR-encrypted with the key thisscert23$SecretKey206.
- C2 packets use the magic number 0xDEADBEEF; communication is mostly JSON, with some commands using JSON headers followed by binary data.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 185[.]235[.]137[.]35 | Backdoor C2 address obtained by decrypting its configuration; the reported port is 9000. |
| SHA256 | a6ceacda670b88e8a8ec9ff5da6a77d9f1c896d6479b2dadb700474a8c408f80 | SHA-256 listed for the malicious side-loaded dgxi.dll. |
| SHA256 | d69d27a94c78889fc8694e13c122438125eb3d3e6023e0624b3137c7f982a852 | SHA-256 listed for the ZIP file containing the malicious DLL and renamed executable. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe backdoor's C2 configuration is XOR-encrypted.T1041 · Exfiltration Over C2 ChannelA backdoor command reads victim files in chunks for download to the C2.T1057 · Process DiscoveryA backdoor command lists processes and retrieves their PIDs, parent PIDs, thread counts, working-set sizes, and paths.T1059.003 · Windows Command ShellThe backdoor can spawn a hidden cmd shell, send input to it, and use cmd.exe /c start when executing non-executable paths.T1082 · System Information DiscoveryThe backdoor sends OS information in its registration beacon and supports a command to send CPU, memory, disk, network, and uptime details.T1083 · File and Directory DiscoveryA backdoor command lists directories and drives.T1105 · Ingress Tool TransferA C2 command uploads a file to the victim as a .tmp file, with another command able to finalize and rename it.T1497.001 · System ChecksThe DLL checks for a debugger and for running analysis tools, including ida.exe, x64dbg.exe, windbg.exe, and ollydbg.exe.T1497.003 · Time Based ChecksThe DLL performs timing checks as part of its anti-debugging and anti-analysis logic.T1547.001 · Registry Run Keys / Startup FolderThe backdoor establishes persistent execution through HKCU\Software\Microsoft\Windows\CurrentVersion\Run.T1574.002 · DLL Side-LoadingA renamed legitimate ApplicationFrameHost.exe side-loads the malicious dgxi.dll.
Vendors
HZ Hosting LtdThe backdoor configuration is XOR encrypted with key thisscert23$SecretKey206. Upon decryption, we obtain the following C2 infrastructure: 185.235.137.35:9000. This IP address is owned by HZ Hosting Ltd.MicrosoftGetModuleFileNameW to retrieve its own path and copying itself and the accompanying DLL to %AppData%\Microsoft\ApplicationHost\. The executable is copied as ApplicationHost.exe. Persistent execution is established
Products
Tools
ida.exeand OutputDebugStringA() timing.It detects the presence of common analysis tools: ida.exe, ida64.exe, x64dbg.exe, x32dbg.exe, windbg.exe, ollydbg.exeIt performs timing and integrity checks.ida64.exeand OutputDebugStringA() timing.It detects the presence of common analysis tools: ida.exe, ida64.exe, x64dbg.exe, x32dbg.exe, windbg.exe, ollydbg.exeIt performs timing and integrity checks. Figure 3:ollydbg.exewindbg.exetiming.It detects the presence of common analysis tools: ida.exe, ida64.exe, x64dbg.exe, x32dbg.exe, windbg.exe, ollydbg.exeIt performs timing and integrity checks. Figure 3: Sample anti-debugging.x32dbg.exetiming.It detects the presence of common analysis tools: ida.exe, ida64.exe, x64dbg.exe, x32dbg.exe, windbg.exe, ollydbg.exeIt performs timing and integrity checks. Figure 3: Sample anti-debugging.x64dbg.exeand OutputDebugStringA() timing.It detects the presence of common analysis tools: ida.exe, ida64.exe, x64dbg.exe, x32dbg.exe, windbg.exe, ollydbg.exeIt performs timing and integrity checks. Figure 3: Sample