A .WAV With A Payload, (Tue, Apr 21st)
ID: e9d3b0cf-11aa-5ebe-b342-9ec641b75ac4
STIX ID: report--e9d3b0cf-11aa-5ebe-b342-9ec641b75ac4
Feed Name: SANS ISC Diary
Threat Score
This short analysis demonstrates a technique where threat actors replace the audio bytes of a .wav file with a BASE64 representation of an XOR-encoded PE executable. The author shows extracting the payload with a base64 dump, recovering the XOR key via a known-plaintext attack targeting the DOS header, and extracting the decoded PE for further analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
