Technical Analysis of TransferLoader
ID: 5fd75414-35ed-5ca4-bd38-887ba62d57ab
STIX ID: report--5fd75414-35ed-5ca4-bd38-887ba62d57ab
Feed Name: Zscaler Security Research Blog
TransferLoader is a modular Windows malware loader that decrypts and executes embedded payloads (commonly a downloader, a backdoor loader, and a backdoor) using custom obfuscation, string encryption, and anti-analysis checks. The report details its decryption chain (custom Base32 + AES variations), anti-VM/debug techniques, two obfuscation methods, downloader behavior (HTTPS fetch, custom XOR decryption, decoy PDF), backdoor loader persistence and pipe-based config management, and the backdoor's network protocol (custom checksum, stream cipher, support for HTTP/TCP, and IPFS fallback). Indicators such as registry keys, named pipe name, HTTP headers, hardcoded keys/hashes, and packet structures are provided to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
