{"id":3122,"date":"2021-06-19T00:47:32","date_gmt":"2021-06-19T05:47:32","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3122"},"modified":"2021-06-19T00:47:33","modified_gmt":"2021-06-19T05:47:33","slug":"matanbuchus-demonic-threat-lurking-on-the-web","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/","title":{"rendered":"Matanbuchus demonic threat lurking on the Web"},"content":{"rendered":"\n<p>Unfortunately for everyone a new threat has appeared called Matanbuchus which is a Loader service (MaaS) created by the BelialDemon group. This is a cybercrime actor who references demonic themes in software and usernames. It has been discovered by cybersecurity experts at Palo Alto Networks Unit 42. The malicious code was announced in February 2021 at a starting rental price of $ 2,500 and was actually released through posts giving other criminals access.<\/p>\n\n\n\n<p>This new threat has unfortunately already affected several organizations in the US and the EU to this day including a large university and high school in the United States, as well as a high-tech organization in Belgium. In addition, Matanbuchus is capable of:<\/p>\n\n\n\n<p><strong><em>\u25b8The ability to run an .exe or .dll file in memory<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Ability to leverage schtasks.exe to add or modify task schedules<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8This threat can launch custom PowerShell commands<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8In addition, it takes advantage of a separate executable to load the DLL if the attacker has no way to do it<\/em><\/strong><\/p>\n\n\n\n<p>This threat seems to be spreading through Phishing so awareness of this is important and thus not fall before these malicious deceptions. At the moment the best thing that one can apply against this threat is to have a good next generation Firewall not only against this threat but against the many others that we could find on the Internet.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/avaddon-the-ransomware-that-uses-ddos-attacks\/\">Avaddon, the ransomware that uses DDoS attacks<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/buer-malware-charger-emerges-on-the-web\/\">Buer Malware Charger Emerges on the Web<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Unfortunately for everyone a new threat has appeared called Matanbuchus which is a Loader service (MaaS) created by the BelialDemon group. This is a cybercrime actor who references demonic themes in software and usernames. It has been discovered by cybersecurity experts at Palo Alto Networks Unit 42. The malicious code was announced in February 2021 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3123,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3122","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-19T05:47:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-19T05:47:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"444\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Matanbuchus demonic threat lurking on the Web\",\"datePublished\":\"2021-06-19T05:47:32+00:00\",\"dateModified\":\"2021-06-19T05:47:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/\"},\"wordCount\":246,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Evil.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/\",\"name\":\"Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Evil.jpg\",\"datePublished\":\"2021-06-19T05:47:32+00:00\",\"dateModified\":\"2021-06-19T05:47:33+00:00\",\"description\":\"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Evil.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Evil.jpg\",\"width\":1000,\"height\":444},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/matanbuchus-demonic-threat-lurking-on-the-web\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Matanbuchus demonic threat lurking on the Web\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog","description":"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/","og_locale":"es_MX","og_type":"article","og_title":"Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog","og_description":"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........","og_url":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-19T05:47:32+00:00","article_modified_time":"2021-06-19T05:47:33+00:00","og_image":[{"width":1000,"height":444,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Matanbuchus demonic threat lurking on the Web","datePublished":"2021-06-19T05:47:32+00:00","dateModified":"2021-06-19T05:47:33+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/"},"wordCount":246,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/","url":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/","name":"Matanbuchus demonic threat lurking on the Web - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg","datePublished":"2021-06-19T05:47:32+00:00","dateModified":"2021-06-19T05:47:33+00:00","description":"As we well know, cybercriminals do not rest and continue to create ways to harm us, such as the new threat called Matanbuchus.........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Evil.jpg","width":1000,"height":444},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/matanbuchus-demonic-threat-lurking-on-the-web\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Matanbuchus demonic threat lurking on the Web"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3122"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3122\/revisions"}],"predecessor-version":[{"id":3137,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3122\/revisions\/3137"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3123"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}