A funny little obfuscation technique
ID: 4e087bd3-996a-5d7d-b000-8b9332f055b7
STIX ID: report--4e087bd3-996a-5d7d-b000-8b9332f055b7
Feed Name: CERT Polska
Threat Score
This report analyzes a two-stage Windows dropper that avoids common unpacker hooks by writing only a tiny stub into a target process and then reading the larger payload from the parent process (using ReadProcessMemory). The sample dynamically resolves APIs (Zeus-style encoding), decrypts an RC4-packed payload, injects via a runPE into svchost.exe, and includes several file hashes for investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
