logo

Snakes on a Domain: An Analysis of a Python Malware Loader | Huntress

ID: a5b91373-33a6-5c65-a8c3-6c3c5ea9032a

STIX ID: report--a5b91373-33a6-5c65-a8c3-6c3c5ea9032a

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

This report details a forensic analysis of a multi-stage malware chain initiated by a persistent sysmon.lnk shortcut that launched a renamed IronPython interpreter and successive staged payloads (six stages) leading to a URSU-family RAT. The analysis documents decoding/unpacking routines (Base64, gzip, custom cipher), process hollowing into msbuild.exe, an AMSI bypass, anti-analysis checks, persistence via run keys and scheduled tasks, C2 configuration extraction, and provides file hashes and domains as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.