Analysis of a UDP worm
ID: 1402a782-3368-5002-a967-68b9f9abf216
STIX ID: report--1402a782-3368-5002-a967-68b9f9abf216
Feed Name: SensePost Blog
This report analyzes a malware sample that achieved persistence by copying itself to the user's AppData and adding a Winlogon registry entry, injected into explorer.exe, and communicated with multiple hardcoded C2 servers over UDP (port 14000) using an obfuscated protocol. The sample used GDI-based timing/evasion techniques to bypass heuristic sandboxing, performed a second-stage decryption and decompression of commands (including changing browser homepage), and contains functionality for USB autorun propagation, remote download-and-execute, and Firefox cookie theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
