logo

The Story Of A Trojan Dropper II

ID: 2099200c-d31a-5caf-b726-d21e3e21574f

STIX ID: report--2099200c-d31a-5caf-b726-d21e3e21574f

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a packed Windows PE sample that performs in-memory decryption and execution of position-independent shellcode, resolves APIs by hashed names, decompresses an embedded PE (aplib), rebuilds its IAT in memory, drops a secondary executable named "Adobe.exe" to the temporary folder, and executes it while also creating a dummy PDF file; the analysis documents the unpacking, decryption, and execution flow and notes upcoming analysis of the dropped payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.