BlueDelta Targets Defense and Diplomacy with HOOKEDGE
BlueDelta (APT28) deployed a lightweight Windows batch-script backdoor called HOOKEDGE against European government and diplomatic targets between September 2025 and April 2026. HOOKEDGE abuses webhook.site for C2, payload staging, and exfiltration, using Microsoft Edge as its HTTP client to blend with legitimate browsing traffic. The backdoor is a direct evolution of the HEADLACE implant, retaining batch-based execution, GUID-named file artifacts, and legitimate internet service abuse while introducing tiered beaconing to manage webhook.site free-tier request limits.
- filename5744c020-a8d9-4755-abfb-cde6ccd450af.vbsInstaller launcher script dropped to %userprofile%. Creates the scheduled task for persistence then self-deletes along with the installer and task definition file.
- filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.batHOOKEDGE main payload batch script dropped to %userprofile% by the malicious Word macro. GUID matches the staging webhook endpoint.
- filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.cmdInstaller script dropped to %userprofile% by the malicious Word macro. Part of the multi-stage installer chain.
- filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.htmExfiltration staging header file dropped to %userprofile%. Used to assemble HTML exfiltration files that auto-submit form data to the exfiltration webhook.
- filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.vbsHOOKEDGE launcher script dropped to %userprofile%. Executed by the scheduled task with the HOOKEDGE payload as its argument.
- filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.xhtmlExfiltration staging footer file dropped to %userprofile%. Combined with the .htm header to wrap command output before exfiltration.
- sha256001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500HOOKEDGE-related sample hash.
- sha256206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991HOOKEDGE-related sample hash.
- sha256231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1HOOKEDGE-related sample hash.
- sha2562793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104HOOKEDGE-related sample hash.
- sha2562e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201bHOOKEDGE-related sample hash.
- sha2562e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667aHOOKEDGE-related sample hash.
- sha25638f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bdHOOKEDGE-related sample hash.
- sha25658cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577eHOOKEDGE-related sample hash.
- sha2565f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076aHOOKEDGE-related sample hash.
- sha25674456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395HOOKEDGE-related sample hash.
- sha2567d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845HOOKEDGE-related sample hash.
- sha256877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77HOOKEDGE-related sample hash.
- sha25687c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3HOOKEDGE-related sample hash.
- sha2568f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44HOOKEDGE-related sample hash.
- sha2569097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fcHOOKEDGE-related sample hash.
- sha2569c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616dHOOKEDGE-related sample hash.
- sha256aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360HOOKEDGE-related sample hash.
- sha256b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4HOOKEDGE-related sample hash.
- sha256b1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcbHOOKEDGE-related sample hash.
- sha256b8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80HOOKEDGE-related sample hash.
- sha256bfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6HOOKEDGE-related sample hash.
- sha256c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44HOOKEDGE-related sample hash.
- sha256c6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00HOOKEDGE-related sample hash.
- sha256df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6HOOKEDGE-related sample hash.
- sha256ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1HOOKEDGE-related sample hash.
- sha256f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6caHOOKEDGE-related sample hash.
- urlhxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0bHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8eHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7dHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacdHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd6HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/5744c020-a8d9-4755-abfb-cde6ccd450afExfiltration webhook endpoint. The GUID matches the filename of the installer launcher file (5744c020-a8d9-4755-abfb-cde6ccd450af.vbs) dropped during installation.
- urlhxxps://webhook[.]site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fbaHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/655a413e-4a66-4987-8f5b-f5cbfe34cdd6HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/68ff1679-974b-4d15-9ce0-799892c63f04HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/752c57b9-20d1-4990-a909-fd212ab71dcdHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/81f3d140-eb6e-4d72-a6ca-e6e952c3d9c2HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/82911ae6-ea27-4996-a664-2322e89da9aeHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/9f2837e2-8321-46a5-aee5-ccdda349f864HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/a3f4e990-0b2a-4f6a-a02e-c573005de3eeHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3dHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/bbdbf60c-8593-4660-9620-d3c0de24a8abHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/c24a31e4-691e-4a7b-96af-037ae735d358HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxps://webhook[.]site/cf25f91c-0a20-4339-834f-02f73e8bc75ePrimary HOOKEDGE staging webhook endpoint. The GUID in this URL matches the filenames of the HOOKEDGE payload, launcher, installer, and exfiltration staging files dropped to disk.
- urlhxxps://webhook[.]site/d993e113-a672-48aa-a382-64c5aaac56ebHOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxp://webhook[.]site/1e72b758-79e4-4c1c-90ed-7a8dc118f105HOOKEDGE webhook endpoint used for C2 or staging.
- urlhxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpgDocument-open canary URL embedded as a hidden image in the malicious Word document. Alerts operators when a victim opens the lure document, capturing the victim IP address.
- urlhxxp://webhook[.]site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/docopened[.]jpgDocument-open canary URL.
- urlhxxp://webhook[.]site/c1d8ba4a-f044-4454-8b1c-b6866518f92c/doc[.]jpgDocument-open canary URL using later variant filename doc.jpg.
- urlhxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/docopened[.]jpgDocument-open canary URL sharing the same webhook endpoint as the mailopened.jpg canary.
- urlhxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/mailopened[.]jpgEmail-open canary URL used to track when phishing emails are opened by recipients, providing operators visibility into campaign delivery success before payload execution.
- urlhxxp://webhook[.]site/c2e1be16-401b-4f60-8a0f-276b30417fda/docopened[.]jpgDocument-open canary URL.
- urlhxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/docopened[.]jpgDocument-open canary URL.
- urlhxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/mailopened[.]jpgEmail-open canary URL sharing the same webhook endpoint as the docopened.jpg canary.
Detection / Hunteropenrouter
What Happened
A Russian government-linked hacking group called BlueDelta used malicious Microsoft Word documents to infect computers at government and diplomatic organizations in Romania, Spain, and Türkiye. The documents contained hidden code that installed a small program called HOOKEDGE, which lets the attackers remotely send commands to the infected computer and steal data. The attackers used a legitimate website called webhook.site to manage their communications, making the malicious traffic hard to distinguish from normal web browsing. Organizations should block macros in documents received from the internet, monitor for suspicious scheduled tasks, and watch for unusual Microsoft Edge browser activity that could indicate this type of compromise.
Key Takeaways
- BlueDelta (APT28/Fancy Bear/Forest Blizzard) deployed a new batch-script backdoor called HOOKEDGE via macro-enabled Word documents targeting government and diplomatic organizations in Romania, Spain, and Türkiye between September 2025 and April 2026.
- HOOKEDGE is a direct evolutionary successor to the HEADLACE backdoor, sharing code structure, batch-based scripting, legitimate internet service abuse for C2, and hidden browser instances for communications.
- The backdoor abuses webhook.site free-tier endpoints for tasking, staging, and exfiltration, using a two-webhook architecture that separates command delivery from data exfiltration.
- BlueDelta uses a tiered operational model: first-stage HOOKEDGE beacons every 30-61 minutes for initial triage, then deploys a second-stage payload with 5-minute beaconing for higher-value targets to preserve webhook request quotas.
- The malware uses msedge.exe for all C2 communications, blending network traffic with legitimate enterprise browsing activity and evading domain reputation and IP-based detection.
Affected Systems
- Microsoft Windows endpoints
- Microsoft Word (macro-enabled documents)
- Microsoft Edge browser
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Spearphishing email delivers macro-enabled Word document with diplomatic-themed or generic lure to government and diplomatic personnel
- Execution: AutoOpen macro writes six GUID-named files (.bat, .vbs, .cmd, .htm, .xhtml) to %userprofile% and launches the installer chain
- Persistence: Installer launcher creates a scheduled task running every 30-61 minutes to execute the HOOKEDGE launcher with the payload as its argument, then self-deletes installer artifacts
- Command and Control: HOOKEDGE uses msedge.exe to poll a staging webhook endpoint for .cmd payloads, which are downloaded as .75e files to %userprofile%\Downloads\
- Execution: Downloaded .75e files are concatenated into a .cmd file and executed on the infected host
- Exfiltration: Command output is wrapped in pre-staged HTML header/footer files and POSTed to a separate exfiltration webhook via a second Edge instance, then temporary files are deleted
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not provide detection rules. It provides IOCs (URLs and hashes) in Appendix A and MITRE ATT&CK technique mappings in Appendix C, along with mitigation guidance for scheduled task monitoring, browser automation detection, and outbound webhook service inspection.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can observe scheduled task creation, process execution of msedge.exe with unusual arguments, and file writes to %userprofile% with GUID-format names. However, msedge.exe is a legitimate browser and its network activity may not raise alerts. The self-deletion of installer artifacts reduces forensic visibility. |
| Network Visibility | Low | All C2 traffic goes to webhook.site over HTTPS via Microsoft Edge, blending with legitimate enterprise browsing. Domain reputation and IP-based detection are ineffective because webhook.site is a legitimate service. TLS inspection policies that exempt trusted services would miss this traffic. The only network indicator is the specific webhook URL path. |
| Detection Difficulty | Hard | HOOKEDGE uses legitimate browser processes for C2, legitimate webhook services for infrastructure, and batch scripts that avoid custom binaries. The combination of LOLBin abuse and legitimate service abuse makes signature-based detection ineffective. Detection requires behavioral correlation across process execution, scheduled task creation, file naming patterns, and network destination analysis. |
Required Log Sources
- Windows Task Scheduler operational log (Event ID 4698)
- Sysmon Event ID 1 (Process Creation) or Windows Security Event ID 4688
- Sysmon Event ID 3 (Network Connection) or Windows Security Event ID 5156
- Sysmon Event ID 11 (File Creation) for GUID-named files in user profile
- Microsoft Edge browser logs or proxy/SWG logs for webhook.site connections
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Scheduled tasks executing batch or VBS scripts from user-writable directories such as %userprofile% may indicate HOOKEDGE persistence. | Windows Task Scheduler Event ID 4698, Sysmon Event ID 1 for schtasks.exe process creation | Persistence (T1053.005) | Medium — legitimate administrative scripts may use scheduled tasks, but execution from user profile directories is uncommon. |
| Microsoft Edge processes launched with --headless=new or hidden window arguments accessing local HTML files may indicate HOOKEDGE C2 or exfiltration activity. | Sysmon Event ID 1 for msedge.exe process creation with command-line arguments, Sysmon Event ID 3 for network connections from msedge.exe | Command and Control (T1071.001) | Low — headless Edge execution with local HTML files is uncommon in enterprise environments. |
| Files with GUID-format names and extensions .bat, .vbs, .cmd, .htm, or .xhtml appearing in the %userprofile% directory may indicate HOOKEDGE installation. | Sysmon Event ID 11 (File Creation), EDR file write telemetry | Execution (T1059.003, T1059.005) | Low — GUID-named script files in user profile directories are atypical for normal user activity. |
| Outbound HTTPS connections from msedge.exe to webhook.site with UUID-formatted URL paths may indicate HOOKEDGE C2, staging, or exfiltration. | Proxy or SWG logs, Sysmon Event ID 3 network connections, DNS resolution logs | Command and Control (T1071.001) and Exfiltration (T1567.004) | Medium — webhook.site is a legitimate service used by developers and testers, but UUID-path access from browser processes is worth investigating. |
| Files with a .75e extension appearing in the Downloads directory may indicate HOOKEDGE payload retrieval from the staging webhook. | Sysmon Event ID 11 (File Creation) in %userprofile%\Downloads, EDR file write telemetry | Ingress Tool Transfer (T1105) | Low — the .75e extension is derived from the last three characters of the staging webhook GUID and is not a standard file extension. |
Control Gaps
- Domain reputation and IP blocklists will not flag webhook.site as malicious because it is a legitimate service.
- TLS inspection policies that exempt trusted or categorized domains will not inspect traffic to webhook.site.
- Network-based detection relying on anomalous TLS fingerprints or non-browser user agents will not trigger because Microsoft Edge is used as the HTTP client.
- Signature-based antivirus may not flag batch scripts and VBS files that use standard Windows interpreters.
- Sandbox environments with execution windows of 60 minutes or less may not capture HOOKEDGE activity when the beacon interval is set to 61 minutes.
Key Behavioral Indicators
- Scheduled task executing wscript.exe or cmd.exe from %userprofile% with GUID-named script files as arguments
- msedge.exe launched with --headless=new or hidden window arguments accessing local file:// URLs
- GUID-format filenames with .bat, .vbs, .cmd, .htm, .xhtml extensions in %userprofile% directory
- Files with .75e extension downloaded to %userprofile%\Downloads directory
- msedge.exe making outbound HTTPS connections to webhook.site URLs containing UUID-format paths
- Multiple msedge.exe instances spawned from cmd.exe or wscript.exe parent processes
- HTML files in %userprofile% containing auto-submit form elements targeting webhook.site endpoints
False Positive Assessment
Low — the combination of GUID-named batch/VBS files in user profile directories, scheduled tasks executing from those paths, and outbound connections to webhook.site UUID endpoints is highly specific to HOOKEDGE activity. Individual indicators such as msedge.exe network activity or scheduled task creation may generate false positives, but the correlation of multiple indicators significantly reduces this risk.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider searching endpoint telemetry for the listed webhook.site URLs, GUID-named files in user profile directories, and scheduled tasks executing scripts from user-writable paths.
- If your EDR supports host isolation, consider isolating any hosts identified as communicating with the listed webhook.site endpoints or exhibiting HOOKEDGE file artifacts.
- Consider blocking outbound connections to webhook.site if the service is not used by your organization for legitimate purposes.
- Evaluate whether any of the 25 listed SHA256 hashes match files present in your environment.
Infrastructure Hardening
- Consider disabling or restricting macro execution from internet-originated Microsoft Office documents using Microsoft's recommended macro-blocking policies.
- If supported by your proxy or SWG, consider implementing alerts for outbound connections to webhook.site with UUID-format URL paths from browser processes.
- Evaluate whether your TLS inspection policy covers webhook.site traffic, as exemption of trusted or categorized domains may allow C2 traffic to pass uninspected.
- Consider deploying phishing-resistant MFA (FIDO2 or certificate-based) for email, VPN, and externally accessible services, as BlueDelta has historically relied on credential theft to expand access.
User Protection
- Consider deploying endpoint detection rules for scheduled task creation that executes scripts from user-writable directories.
- If your EDR supports it, consider alerting on msedge.exe execution with --headless=new or hidden window arguments, particularly when accessing local file:// URLs.
- Consider monitoring for GUID-format filenames with script extensions (.bat, .vbs, .cmd) appearing in user profile directories.
Security Awareness
- Consider incorporating guidance into existing awareness programs about enabling macros in documents received from external or unknown senders, particularly diplomatic-themed documents.
- If applicable to your organization, consider reminding staff that legitimate government documents do not require macro enablement to view content.
- Consider educating users to report Word documents that display fake error messages after enabling content, as this is a known BlueDelta social engineering technique.
MITRE ATT&CK Mapping
Resource Development
Execution
Stealth
Discovery
Collection
Command and Control
Exfiltration
Additional IOCs
- Urls:
hxxp://webhook[.]site/1e72b758-79e4-4c1c-90ed-7a8dc118f105- HOOKEDGE webhook endpoint used for C2 or staging.hxxp://webhook[.]site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/docopened.jpg- Document-open canary URL.hxxp://webhook[.]site/c1d8ba4a-f044-4454-8b1c-b6866518f92c/doc.jpg- Document-open canary URL using later variant filename doc.jpg.hxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/docopened.jpg- Document-open canary URL sharing the same webhook endpoint as the mailopened.jpg canary.hxxp://webhook[.]site/c2e1be16-401b-4f60-8a0f-276b30417fda/docopened.jpg- Document-open canary URL.hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/docopened.jpg- Document-open canary URL.hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/mailopened.jpg- Email-open canary URL sharing the same webhook endpoint as the docopened.jpg canary.hxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0b- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8e- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacd- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd6- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fba- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/655a413e-4a66-4987-8f5b-f5cbfe34cdd6- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/68ff1679-974b-4d15-9ce0-799892c63f04- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/752c57b9-20d1-4990-a909-fd212ab71dcd- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/81f3d140-eb6e-4d72-a6ca-e6e952c3d9c2- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/82911ae6-ea27-4996-a664-2322e89da9ae- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/9f2837e2-8321-46a5-aee5-ccdda349f864- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/a3f4e990-0b2a-4f6a-a02e-c573005de3ee- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3d- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/bbdbf60c-8593-4660-9620-d3c0de24a8ab- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/c24a31e4-691e-4a7b-96af-037ae735d358- HOOKEDGE webhook endpoint used for C2 or staging.hxxps://webhook[.]site/d993e113-a672-48aa-a382-64c5aaac56eb- HOOKEDGE webhook endpoint used for C2 or staging.
- File Hashes:
001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500(SHA256) - HOOKEDGE-related sample hash.206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991(SHA256) - HOOKEDGE-related sample hash.231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1(SHA256) - HOOKEDGE-related sample hash.2793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104(SHA256) - HOOKEDGE-related sample hash.2e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201b(SHA256) - HOOKEDGE-related sample hash.2e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667a(SHA256) - HOOKEDGE-related sample hash.38f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bd(SHA256) - HOOKEDGE-related sample hash.58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e(SHA256) - HOOKEDGE-related sample hash.5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a(SHA256) - HOOKEDGE-related sample hash.74456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395(SHA256) - HOOKEDGE-related sample hash.7d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845(SHA256) - HOOKEDGE-related sample hash.877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77(SHA256) - HOOKEDGE-related sample hash.87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3(SHA256) - HOOKEDGE-related sample hash.8f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44(SHA256) - HOOKEDGE-related sample hash.9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc(SHA256) - HOOKEDGE-related sample hash.9c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616d(SHA256) - HOOKEDGE-related sample hash.aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360(SHA256) - HOOKEDGE-related sample hash.b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4(SHA256) - HOOKEDGE-related sample hash.b1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcb(SHA256) - HOOKEDGE-related sample hash.b8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80(SHA256) - HOOKEDGE-related sample hash.bfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6(SHA256) - HOOKEDGE-related sample hash.c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44(SHA256) - HOOKEDGE-related sample hash.c6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00(SHA256) - HOOKEDGE-related sample hash.df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6(SHA256) - HOOKEDGE-related sample hash.ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1(SHA256) - HOOKEDGE-related sample hash.f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca(SHA256) - HOOKEDGE-related sample hash.
- Command Lines:
- Purpose: Create scheduled task for HOOKEDGE persistence, launching the VBS launcher with the BAT payload as an argument every 30-61 minutes | Tools:
schtasks.exe,wscript.exe| Stage: Persistence |schtasks /create /tn <taskname> /tr - Purpose: Launch Microsoft Edge to retrieve command payloads from staging webhook or exfiltrate data to exfiltration webhook | Tools:
msedge.exe| Stage: Command and Control |msedge.exe --headless=new
- Purpose: Create scheduled task for HOOKEDGE persistence, launching the VBS launcher with the BAT payload as an argument every 30-61 minutes | Tools: