Deobfuscating a Dropper for a ZLoader Trojan Variant
ID: 5919277d-8a1e-5b07-9704-c51689fb2b6f
STIX ID: report--5919277d-8a1e-5b07-9704-c51689fb2b6f
Feed Name: WatchGuard Secplicity Blog
On March 18, 2021 DNSWatch analysts analyzed a heavily obfuscated Visual Basic Script attachment (Attachment_57904.vbs) delivered via email; the script decodes many arrays to reconstruct a ZIP (assai.zip) that contains numerous small files and Rabin.dmg — which is actually a 32-bit DLL and a variant of the ZLoader (Ursnif/Gozi) banking/infostealer. The report documents the deobfuscation process, provides file hashes and external analysis links, shows screenshots of the code and extraction steps, and recommends mitigations such as email filtering, endpoint signatures, user training, and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
