XLoader Executed Through JAR Signing Tool (jarsigner.exe)
ID: 34640f4b-8068-50cf-8e82-55d78557581f
STIX ID: report--34640f4b-8068-50cf-8e82-55d78557581f
Feed Name: ASEC
AhnLab ASEC discovered a distribution campaign of the XLoader infostealer using DLL side-loading: attackers bundle a legitimate, signed jarsigner EXE (renamed Documents2012.exe) with two unsigned malicious DLLs (jli.dll and concrt140e.dll). The tampered jli.dll exports a single malicious entry point that decrypts concrt140e.dll and injects it into aspnet_wp.exe; the decrypted payload executes XLoader to harvest system and browser data and download additional malware. The report includes two MD5 hashes and a delivery URL as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
