logo

A funny little obfuscation technique

ID: 4e087bd3-996a-5d7d-b000-8b9332f055b7

STIX ID: report--4e087bd3-996a-5d7d-b000-8b9332f055b7

Feed Name: CERT Polska

Threat Score
55/100

Date Published: 2015-09-09

Date Updated: 2026-04-19

Author: mak

...
...

This report analyzes a two-stage Windows dropper that avoids common unpacker hooks by writing only a tiny stub into a target process and then reading the larger payload from the parent process (using ReadProcessMemory). The sample dynamically resolves APIs (Zeus-style encoding), decrypts an RC4-packed payload, injects via a runPE into svchost.exe, and includes several file hashes for investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.