logo

Redosdru — Encrypting DLL Payloads to Avoid On-Disk Signatures

ID: 4664f8d5-c851-5a98-b550-a2ece124505f

STIX ID: report--4664f8d5-c851-5a98-b550-a2ece124505f

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2017-07-17

Date Updated: 2026-04-28

...
...

Malware analysis documents a UPX-packed dropper (wshom.exe) that retrieves an encrypted NetSyst88.dll from http://xiqiao2.f3322.org:2014, decrypts it in memory, and loads an implant (linked to Redosdru) capable of keystroke logging, user/group manipulation, process killing and clipboard theft; analysis includes SHA256 hashes and network IOCs validated with ProcMon and Wireshark.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.