Backdoor Xtrat Continues To Evade Detection
ID: 6c1b712a-81ac-5c95-9149-869cb163c1a0
STIX ID: report--6c1b712a-81ac-5c95-9149-869cb163c1a0
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Zscaler observed a live example of the Backdoor Xtrat malware distributed from a malicious PHP URL that delivered a ZIP containing an EXE; the report includes file MD5s, VirusTotal detection counts, dropped filenames, network indicators (C2 domains, an IP and ports), observed behaviors (process injection, dropped PE files, remote command/data exfiltration), and suggested Snort signatures — noting the malware is older but remains active with many changing C2 domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
