Date: 09/16/2026
Severity: High
Summary
A malware campaign uses a fake Indian Income Tax Department assessment notice to distribute a RAT-like payload targeting Windows systems. The attackers operate ten malicious domains hosting a fraudulent tax assessment portal designed to mimic official government communications. Victims are tricked into downloading a malicious VHDX file disguised as an official ITR-1 to ITR-4 offline utility for FY2025–26. The mounted VHDX delivers a loader executable and malicious `tedutil.dll`, which is extracted from the executable’s embedded resources and executed. The staged malware provides RAT-like capabilities, including persistence, system reconnaissance, command execution, and remote communication.
Indicators of Compromise (IOC) List
Domain/URLs | zasxcd.shop ssefcv.shop cbvfrd.shop bvnbhy.shop bmnjhy.shop mkjiun.shop nmhjnu.shop zxcdfr.shop sfbnhy.shop xvbndr.shop |
IP Address | 103.59.103.170 103.97.128.245 |
Hash | 518ee4c9ae0321bd4fe8616e4f195f0079c6503109d2710e80e09d1a0f1dc98f
f4ae0f7c0c663e41dab28b2992f1afa9b97fe13a52f2d1fa26156554a23b99a7
71d15f3c13f5b11866cf65d9cf014236a47d221155ae992d9992abccedb66cf2
|
Filename | Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "cbvfrd.shop" or url like "cbvfrd.shop" or siteurl like "cbvfrd.shop" or domainname like "sfbnhy.shop" or url like "sfbnhy.shop" or siteurl like "sfbnhy.shop" or domainname like "zxcdfr.shop" or url like "zxcdfr.shop" or siteurl like "zxcdfr.shop" or domainname like "xvcbvgfr.com" or url like "xvcbvgfr.com" or siteurl like "xvcbvgfr.com" or domainname like "bmnjhy.shop" or url like "bmnjhy.shop" or siteurl like "bmnjhy.shop" or domainname like "bvnbhy.shop" or url like "bvnbhy.shop" or siteurl like "bvnbhy.shop" or domainname like "nmhjnu.shop" or url like "nmhjnu.shop" or siteurl like "nmhjnu.shop" or domainname like "ssefcv.shop" or url like "ssefcv.shop" or siteurl like "ssefcv.shop" or domainname like "xvbndr.shop" or url like "xvbndr.shop" or siteurl like "xvbndr.shop" or domainname like "mkjiun.shop" or url like "mkjiun.shop" or siteurl like "mkjiun.shop" or domainname like "zasxcd.shop" or url like "zasxcd.shop" or siteurl like "zasxcd.shop" |
Detection Query 2 : | dstipaddress IN ("103.59.103.170","103.97.128.245") or srcipaddress IN ("103.59.103.170","103.97.128.245") |
Detection Query 3 : | sha256hash IN ("71d15f3c13f5b11866cf65d9cf014236a47d221155ae992d9992abccedb66cf2","f4ae0f7c0c663e41dab28b2992f1afa9b97fe13a52f2d1fa26156554a23b99a7","518ee4c9ae0321bd4fe8616e4f195f0079c6503109d2710e80e09d1a0f1dc98f")
|
Reference:
https://www.cyfirma.com/research/fake-tax-themed-phishing-campaign-delivers-malware/