SLOTAGENT Obfuscation Tactics Challenge Security Researchers
ID: a8892ea0-0648-5985-b8ef-0bd524d2ad3b
STIX ID: report--a8892ea0-0648-5985-b8ef-0bd524d2ad3b
Feed Name: Cyber Press
SLOTAGENT is a sophisticated Remote Access Trojan delivered via a malicious ZIP that launches a loader (WindowsOobeAppHost.AOT.exe / .dll), resolves Windows APIs via custom hashing, executes Beacon Object File payloads in-memory, and employs timestomping and string encryption (TEA-like) plus DJB2/ROR11 hashing to evade analysis; it communicates over TCP to hardcoded C2 43.156.59.110:699 using a JSON-based protocol and analysts published an IDAPython script to statically decrypt its strings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
