Skip to content

Commit 0050552

Browse files
authored
Merge pull request #1128 from splunk/lotus
Lotus Blossom
2 parents f552270 + 298b180 commit 0050552

File tree

6 files changed

+48
-0
lines changed

6 files changed

+48
-0
lines changed
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Michael Haag, Splunk
2+
id: 5010d236-00a5-434f-bfeb-20af07d478aa
3+
date: '2026-02-02'
4+
description: Lotus Blossom TinyCC shellcode execution simulation. Svchost.exe executed with TinyCC compiler flags (-nostdlib -run) to simulate Chrysalis backdoor's shellcode compilation technique.
5+
environment: attack_range
6+
directory: lotus_blossom_chrysalis
7+
mitre_technique:
8+
- T1059.005
9+
datasets:
10+
- name: windows-sysmon.log
11+
path: /datasets/attack_techniques/T1059.005/lotus_blossom_chrysalis/windows-sysmon.log
12+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:cb5ea7112ec60ef8c6c4abfe3f2d5eccb0d7e8435e0da8ffdc7ff276878e7caf
3+
size 4713
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Michael Haag, Splunk
2+
id: bfab9adc-3767-487a-87cd-35f1a7cd8706
3+
date: '2026-02-02'
4+
description: Lotus Blossom BluetoothService persistence test execution. Service created in user AppData directory for persistence.
5+
environment: attack_range
6+
directory: lotus_blossom_chrysalis
7+
mitre_technique:
8+
- T1543.003
9+
datasets:
10+
- name: windows-system.log
11+
path: /datasets/attack_techniques/T1543.003/lotus_blossom_chrysalis/windows-system.log
12+
sourcetype: XmlWinEventLog:System
13+
source: XmlWinEventLog:System
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a93c337278af4bd34e2cb4ebebf32144a6827d40f760d0ecb6dbd80be2370f8e
3+
size 2326
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Michael Haag, Splunk
2+
id: 66eb3815-e429-4bc2-a8f1-e3ea8bc7e8c2
3+
date: '2026-02-02'
4+
description: Lotus Blossom Bitdefender DLL side-loading test execution. Rundll32.exe loading malicious log.dll from user directory mimicking Bitdefender Submission Wizard abuse.
5+
environment: attack_range
6+
directory: lotus_blossom_chrysalis
7+
mitre_technique:
8+
- T1574.002
9+
datasets:
10+
- name: windows-sysmon.log
11+
path: /datasets/attack_techniques/T1574.002/lotus_blossom_chrysalis/windows-sysmon.log
12+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
13+
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:66dad57f32a2178a924c5742ac7b68fa74d745d9efb8ac7796067e3464b9307c
3+
size 9226

0 commit comments

Comments
 (0)