Technical Analysis of Zloader 2.9.4.0
ID: 1982a212-664f-58fe-8a12-482d96087460
STIX ID: report--1982a212-664f-58fe-8a12-482d96087460
Feed Name: Zscaler Security Research Blog
Threat Score
This technical analysis details Zloader 2.9.4.0 enhancements — computed RC4 configuration keys, modified anti-analysis and API resolution, an interactive shell for remote control, HTTPS-based C2 with SSPI TLS, and a custom DNS tunneling protocol that encapsulates TLS over A/AAAA records — and documents botnet IDs, IoCs (domains/IPs), and ties between a Zloader botnet ID and Black Basta ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
