A new shellcode in the wild
ID: 73ac7f3f-66f4-5e5f-aea4-d0df09b8c784
STIX ID: report--73ac7f3f-66f4-5e5f-aea4-d0df09b8c784
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ analyzes a.NET sample that uses the "Frenchy" shellcode—identified by a mutex name like "frenchy_shellcode_{version}"—to perform hollow process injection and load AES-encrypted payloads; the report details resource extraction, environment checks, persistence (AppData Tasks copy, VBS and URL startup), DLL mapping to evade API monitoring, and lists numerous affected malware families and associated MD5 indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
