Demystifying the Crypter Used in Emotet, Qbot, Dridex
ID: 4c807f31-8a92-568b-8aef-1ebc782145ee
STIX ID: report--4c807f31-8a92-568b-8aef-1ebc782145ee
Feed Name: Zscaler Security Research Blog
Threat Score
### Executive summary This report analyzes a polymorphic crypter observed protecting Emotet, Qbot, and Dridex payloads and describes five stages of obfuscation and encryption, providing heuristics and pseudo-code to locate chunk descriptor tables, reconstruct scattered encrypted chunks, derive the encryption key, normalize PE alignment, and restore moved instructions to recover the core malware binary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
