Cutting Through the Noise: A Technique-Based Approach to Hunting Web-Delivered Malware
ID: c65b5f70-b72a-5742-a98d-ee60618c8849
STIX ID: report--c65b5f70-b72a-5742-a98d-ee60618c8849
Feed Name: Censys Blog
This report describes a technique-based Censys HTTP-body hunt that discovered a ClickFix social-engineering campaign hosted on orcanmedikal.com.tr which delivered a steganography-backed PhantomVAI .NET loader (embedded in a JPEG) that reverses and base64-decodes a staged payload and process-hollows to deploy XWorm V5.6; the analysis includes static recovery of the XWorm binary, extraction of its AES-encrypted configuration (C2: 86.106.85.194:9000), file hashes, IOCs, and recommended host/network detection priorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
