Malware Under The Microscope: Manual Analysis
ID: b01869b6-41dd-5f14-a263-c77f11c334d1
STIX ID: report--b01869b6-41dd-5f14-a263-c77f11c334d1
Feed Name: Huntress Blog
Huntress investigated a malware infection identified as VBS/Satoban.A that used an unusual technique: deploying an old Windows XP svchost.exe binary from C:\Windows\System32\system to load a service configuration (msg) which executed C:\security\system.vbs; that script invoked a renamed wscript.exe to run an encoded VBScript (C:\security\blood.dat) that provides persistence, USB propagation, shadow volume deletion, and downloads additional payloads. The report includes decoded script observations, a list of filesystem artifacts and potential malicious domains, and recommends deeper code-path analysis and automated detections to find similar footholds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
