Havoc Across the Cyberspace
ID: d0adbdb8-6340-5a0d-a92c-9b33314dbe6f
STIX ID: report--d0adbdb8-6340-5a0d-a92c-9b33314dbe6f
Feed Name: Zscaler Security Research Blog
This report analyzes an in-the-wild campaign delivering the Havoc Demon post-exploitation implant: infection begins with a ZIP containing a BAT2EXE-compiled screensaver downloader that retrieves a signed shellcode loader (pics.exe) from http://146.190.48.229, which decrypts and executes a KaynLdr shellcode to reflectively map the Havoc DLL; the analysis documents ETW patching, API hashing, RWX allocation, AES-encrypted C2 communications, configuration values, available commands, and supporting IoCs and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
