ThreatLabz
ID: b1547930-72ca-5d87-839c-101921e193bf
STIX ID: report--b1547930-72ca-5d87-839c-101921e193bf
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of Xloader (Formbook) 4.3, describing its ConfigObj global structure, encrypted PUSHEBP data blocks and functions, custom decryption algorithms (custom RC4, buffer decryption, and modified SHA1), multi-layer C2 encryption handling (including Base64 and stacked RC4 layers), and a registration packet construction bug that omits version/OS/username fields. It documents how keys are derived and how encrypted functions are delimited/decrypted, and references reproduced tooling to decrypt strings and C2 lists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
