news.mlab.sh
Back to the feed
malware

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

High
Image: SANS Internet Storm Center
Summary

A malspam campaign delivered a malicious attachment containing a LausivLoader script. The script, after removing comments, obfuscated code, and attempts to register a scheduled task, ultimately downloaded and executed a second .NET executable. This executable, in turn, downloaded a PNG image containing a hidden payload, leveraging an 'iTXt' chunk to conceal the malicious code. The entire process involved multiple stages, including data exchange via environment variables and attempts to evade security measures like AMSI.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.