The Story Of A Trojan Dropper III
ID: 64ee5a9c-799d-540e-8a60-c3a50c23050c
STIX ID: report--64ee5a9c-799d-540e-8a60-c3a50c23050c
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** This analysis examines a Trojan dropper ("Adobe.exe") that uses a custom packer, repeated XOR decryption, control-flow obfuscation, and multiple anti-analysis checks (PEB/NtGlobalFlag, filename/path checks, volume serial comparisons, registry Disk\Enum VM-string checks, EnumSystemLocalesA trick, and sbiedll sandbox detection) before decompressing an embedded PE payload with aplib.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
