logo

The Story Of A Trojan Dropper III

ID: 64ee5a9c-799d-540e-8a60-c3a50c23050c

STIX ID: report--64ee5a9c-799d-540e-8a60-c3a50c23050c

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** This analysis examines a Trojan dropper ("Adobe.exe") that uses a custom packer, repeated XOR decryption, control-flow obfuscation, and multiple anti-analysis checks (PEB/NtGlobalFlag, filename/path checks, volume serial comparisons, registry Disk\Enum VM-string checks, EnumSystemLocalesA trick, and sbiedll sandbox detection) before decompressing an embedded PE payload with aplib.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.