ThreatLabz
ID: 5e1a420b-0802-551c-8e6d-850ba13bed8e
STIX ID: report--5e1a420b-0802-551c-8e6d-850ba13bed8e
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of the Pikabot malware, detailing its injector and core module anti-analysis checks (exception handlers, PEB flags, debugger checks, rdtsc, hardware-breakpoint/trap-flag detection), payload decryption (PNG resource XOR + AES-CBC), process injection and protection, persistence via Run keys and PowerShell stored in HKCU, encrypted C2 configuration and traffic (Base64/AES with embedded keys and IVs), supported remote tasks (cmd, shellcode, dll, exe, data collection), and network registration behavior; it also notes campaign identifiers and similarities to Qakbot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
