BOFの実行などに対応した新たなマルウェアSLOTAGENT
ID: 9190c651-3245-5ef8-bf26-1c31398852bb
STIX ID: report--9190c651-3245-5ef8-bf26-1c31398852bb
Feed Name: IIJ Security Diary
IIJ identified and analyzed a multifunctional remote access trojan (SLOTAGENT) found in a public malware repository. The report describes the loader and shellcode (reflective loading, RC4/XOR decryption), API hashing and string encryption anti-analysis techniques, the custom TCP C2 protocol to 43.156.59.110:699, an extensive set of remote commands (including BOF execution, timestomping, memory dumping, file transfer and remote shell), and supplies IoCs (SHA256 hashes, C2 IP) plus YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
