Obfuscation, reflective injection and domain fronting; oh my!
ID: 43727cdd-bce2-5bae-801b-d8d294c14f56
STIX ID: report--43727cdd-bce2-5bae-801b-d8d294c14f56
Feed Name: Expel Blog
This blog post documents a layered malware analysis of a red team VBScript (settings.vbs) that set COMPLUS versioning, decoded large base64 blobs, and reflectively injected a .NET DLL (uqatarcu.dll) which in turn unpacked additional DLLs and an executable (dropper_cs.exe). Using base64dump/pecheck and DotPeek the analyst recovered a PoshC2 implant configured to use domain fronting (appearing to contact paypal.com while setting Host headers to update-crl.azureedge.net), described the in-memory reflective injection and shellcode deployment techniques, and extracted indicators and detection notes for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
