logo

Malware Under The Microscope: Manual Analysis

ID: b01869b6-41dd-5f14-a263-c77f11c334d1

STIX ID: report--b01869b6-41dd-5f14-a263-c77f11c334d1

Feed Name: Huntress Blog

Threat Score
60/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress investigated a malware infection identified as VBS/Satoban.A that used an unusual technique: deploying an old Windows XP svchost.exe binary from C:\Windows\System32\system to load a service configuration (msg) which executed C:\security\system.vbs; that script invoked a renamed wscript.exe to run an encoded VBScript (C:\security\blood.dat) that provides persistence, USB propagation, shadow volume deletion, and downloads additional payloads. The report includes decoded script observations, a list of filesystem artifacts and potential malicious domains, and recommends deeper code-path analysis and automated detections to find similar footholds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.