Technical Analysis of Zloader Updates
ID: ffcb32e2-f3ca-5473-bf40-d42d72689b34
STIX ID: report--ffcb32e2-f3ca-5473-bf40-d42d72689b34
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of recent Zloader updates: the malware now accepts generic filenames (Updater.exe/Updater.dll), adds XOR-based obfuscation and integrity-level checks to evade sandboxes, changes its static configuration format (including a mini JSON for DNS resolvers), replaces TLS in its DNS tunneling with Base32 plus a custom XOR-based decode using a session key, adds WebSocket support to blend with legitimate traffic, and introduces LDAP functions in its interactive shell to improve network discovery and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
