logo

Modiloader From Obfuscated Batch File, (Mon, Dec 23rd)

ID: db1ffebc-27c5-5b55-9f9b-831f7beaf39d

STIX ID: report--db1ffebc-27c5-5b55-9f9b-831f7beaf39d

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2024-12-23

Date Updated: 2026-04-19

...
...

Technical analysis of an email-delivered malicious archive (Albertsons_payment.GZ) that contains an obfuscated Windows batch loader which uses string slicing and LOLBIN abuse (extrac32, certutil) to decode and drop a Delphi-based Modiloader (spoolsv.com, SHA256: baa12b649fddd77ef62ecd2b3169fab9bb5fbe78404175485f9a7fb48dc4456d) that attempted to fetch a secondary stage from https://swamfoxinnc.com/233_Svcrhpjadgy; the report includes observed behaviors, extraction/deobfuscation details, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.