logo

Shellcode Encoded in UUIDs, (Mon, Mar 10th)

ID: 6e9f12aa-de23-5b75-b1f9-ed5617ed2fe4

STIX ID: report--6e9f12aa-de23-5b75-b1f9-ed5617ed2fe4

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-04-19

...
...

A researcher describes a malicious Python script that hides x86 Cobalt Strike shellcode as UUID strings, decodes them using Rpcrt4!UuidFromStringA via ctypes, and injects the resulting bytes into memory to beacon to an HTTP C2 (http://182.61.60.141:6666/tFl6). The sample (SHA256 63733d412c82958055a8125e1499d695aa1e810b3577c6e849a90012c52da929) has low antivirus detection, and the technique has historical precedent with sophisticated actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.