Shellcode Encoded in UUIDs, (Mon, Mar 10th)
ID: 6e9f12aa-de23-5b75-b1f9-ed5617ed2fe4
STIX ID: report--6e9f12aa-de23-5b75-b1f9-ed5617ed2fe4
Feed Name: SANS ISC Diary
Threat Score
A researcher describes a malicious Python script that hides x86 Cobalt Strike shellcode as UUID strings, decodes them using Rpcrt4!UuidFromStringA via ctypes, and injects the resulting bytes into memory to beacon to an HTTP C2 (http://182.61.60.141:6666/tFl6). The sample (SHA256 63733d412c82958055a8125e1499d695aa1e810b3577c6e849a90012c52da929) has low antivirus detection, and the technique has historical precedent with sophisticated actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
