Dissecting SSLoad Malware: A Comprehensive Technical Analysis
ID: 56efe462-e61b-524d-86a0-d6256e1616ce
STIX ID: report--56efe462-e61b-524d-86a0-d6256e1616ce
Feed Name: Intezer Blog
SSLoad is a modular, evolving malware campaign active since April 2024 that uses a novel patched DLL loader (PhantomLoader), self-modifying techniques, and a Rust-based downloader to retrieve additional payloads (including Cobalt Strike). Deliveries observed include phishing with decoy documents and MSI installers; the malware uses custom XOR/RC4 string decoding, API/PEB-based function resolution, Telegram as a dead-drop for C2 discovery, and communicates with a C2 at 85.239.53.219; multiple SHA256 file IOCs are published in the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
