logo

Obfuscation, reflective injection and domain fronting; oh my!

ID: 43727cdd-bce2-5bae-801b-d8d294c14f56

STIX ID: report--43727cdd-bce2-5bae-801b-d8d294c14f56

Feed Name: Expel Blog

Threat Score
60/100

Date Published: 2020-05-26

Date Updated: 2026-04-27

Author: Britton Manahan

...
...

This blog post documents a layered malware analysis of a red team VBScript (settings.vbs) that set COMPLUS versioning, decoded large base64 blobs, and reflectively injected a .NET DLL (uqatarcu.dll) which in turn unpacked additional DLLs and an executable (dropper_cs.exe). Using base64dump/pecheck and DotPeek the analyst recovered a PoshC2 implant configured to use domain fronting (appearing to contact paypal.com while setting Host headers to update-crl.azureedge.net), described the in-memory reflective injection and shellcode deployment techniques, and extracted indicators and detection notes for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.