XenoRAT Adopts Excel XLL Files and ConfuserEx as Access Method
ID: 0ecb2fe3-edbe-5097-9729-5e0fcb250c1f
STIX ID: report--0ecb2fe3-edbe-5097-9729-5e0fcb250c1f
Feed Name: Hunt.io Blog
Threat Score
This report analyzes a XenoRAT remote-access tool delivered as an Excel XLL (Payment_Details.xll) using Excel‑DNA and protected with ConfuserEx; it details the dropper chain (obfuscated batch, passworded SFX RAR, extracted executables), visible decoy PDF, extracted XenoRAT payload (Original.exe) with a hardcoded C2 (87.120.116.115:1391), and provides file and network observables for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
