Xloader deep dive: Link-based malware delivery via SharePoint impersonation · Blog · Sublime Security
ID: f6b00935-041b-5003-b7ae-a6b6dcb52916
STIX ID: report--f6b00935-041b-5003-b7ae-a6b6dcb52916
Feed Name: Sublime Security Blog
Sublime detected a SharePoint impersonation phishing message that delivered a ZIP containing an AutoIT executable which decoded embedded shellcode. The shellcode (execution offset 0x23b0) implements CRC32 API hashing, anti-emulation checks (GetTickCount/Sleep), spawns svchost/netsh for process injection, loads a second ntdll, and injects into explorer.exe; extracted strings (including "PKT2" + base64) and behavioral indicators match XLoader/Formbook, while the initial AutoIT packing resembles TrickGate-style loaders. The post walks through static and dynamic analysis (Ghidra, x32dbg/BlobRunner, hollows_hunter) used to identify the campaign and associated IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
