logo

ThreatLabz

ID: a60c108e-985c-5a1b-b77d-147329ceaea8

STIX ID: report--a60c108e-985c-5a1b-b77d-147329ceaea8

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Xloader (formerly Formbook) is an active information-stealing malware sold as a Malware-as-a-Service; this report analyzes the Windows variant’s C2 communication protocol and multi-layer encryption, including custom virtual machine decryption, RC4-derived keys, and character substitution/encoding used in GET/POST payloads. The analysis explains how decoy domains are embedded, how the real C2 is recovered, and documents sample-specific key-derivation behavior and IOCs (SHA256 and C2 URLs) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.