CIRCL - Old account · @circl
117 followers · 607 posts · Server mastodon.opencloud.lu

2019-12-28: Loader -> '1079' Core Bot
Cert: [LIT-DAN UKIS UAB]
Crypter
CryptStringToBinaryA -> malloc -> window (hide)-> memcpy -> resource -> VirtualAllocExNuma -> Crypto Key Decrypt
Same '1079'

twitter.com/VK_Intel/status/12 …
h/t @malwrhunterteampic.twitter.com/Ow9ZZIktEr

#Sectigo #malware #TrickBot

Last updated 5 years ago