Corvane Aerospace · Incident Response CVN-IR-0442
Open

MiniBrowse relay recovered from a sinkholed host

A partner CERT handed us a sinkholed copy of a relay used against a Corvane Aerospace laptop. The victim opened a ZIP from a fake Nimbus Manticore careers portal. Before the sinkhole took the domain, the relay logged three check-in attempts. The attached capture holds all three, straight off the wire.

Evidence

PCAP sinkhole_capture.pcap 3 sessions · 3.4 KB
R. Okafor · Malware RE

Public reporting on this family states it aborts on an HTTP 200 response and proceeds only otherwise. All three sessions in the capture came back 200.

Recovered from the same host: MiniJunk's single-byte XOR key for this build is 84. It applies once the live relay stops answering 200.

Live relay

A live, non-sinkholed copy of the same relay answers at this host, port 9190, endpoint /checkin. Nothing here needs a real infected host or a real browser. Read the capture, work out what the implant sends and expects back, and reproduce it yourself against the live relay.