Latrodectus updates to version 1.4 with AES-256 string encryption
2024-8-20 17:10:9 Author: www.vmray.com(查看原文) 阅读量:8 收藏

We found a new Latrodectus version (1.4) which switched its string encryption routine to AES-256. 

This new version also utilizes the /test/ C2 endpoint, indicating that it is an early testing sample for this version.

See why we think this is malicious in plain language.

See the whole path of the sample’s execution

Map the malicious activities on the MITRE ATT&CK Framework

Explore detailed information on the IP addresses, URLs and DNS, including function logs and PCAP Streams

Download the IOCs and artifacts to have a clear picture of the threat.

Download the files that the malware downloads, drops or modifies.

Explore how you can use these insights


文章来源: https://www.vmray.com/latrodectus-updates-to-version-1-4-with-aes-256-string-encryption/
如有侵权请联系:admin#unsafe.sh