WINELOADER Analysis
ID: 3d89d84b-d95b-57bb-9ab8-dba4c39d711b
STIX ID: report--3d89d84b-d95b-57bb-9ab8-dba4c39d711b
Feed Name: Zscaler Security Research Blog
### Executive summary The report provides a detailed technical analysis of a targeted phishing campaign that distributes the WINELOADER malware via a malicious PDF linking to an HTA; the HTA stages a signed Microsoft executable and a malicious vcruntime DLL for DLL side-loading, after which WINELOADER decrypts modules with a hardcoded RC4 key, performs DLL hollowing, communicates with C2 using encrypted HTTP beacon payloads, and establishes persistence via a scheduled task or registry Run key. The document includes IOCs (URLs, file names, task name), C2 protocol structure, and mitigation-relevant TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
