Inside Zloader’s Latest Trick: DNS Tunneling
Tags
Common Information
Type | Value |
---|---|
UUID | af2885bf-f7c8-4159-adbe-bddf7222425b |
Fingerprint | ac3070350e3bb251 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Dec. 10, 2024, 3:35 p.m. |
Added to db | Dec. 10, 2024, 5:28 p.m. |
Last updated | Dec. 20, 2024, 12:03 p.m. |
Headline | Inside Zloader’s Latest Trick: DNS Tunneling |
Title | Inside Zloader’s Latest Trick: DNS Tunneling |
Detected Hints/Tags/Attributes | 69/2/22 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 158 | ✔ | Malware Analysis, News and Indicators - Latest topics | https://malware.news/latest.rss | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 3 | ns1.brownswer.com |
|
Details | Domain | 1 | deployment.network |
|
Details | Domain | 5 | bigdealcenter.world |
|
Details | Domain | 87 | www.zscaler.com |
|
Details | File | 1 | protocol.key |
|
Details | File | 1 | sessions.inf |
|
Details | File | 1 | shell.tab |
|
Details | File | 1 | 0hexaport.exe |
|
Details | File | 3 | syncsuite.exe |
|
Details | File | 2 | omniscript.dll |
|
Details | File | 2 | pixelsignal.dll |
|
Details | File | 1 | 1hexalab.dll |
|
Details | File | 2 | hexaport.dll |
|
Details | File | 1 | 1hexaport.dll |
|
Details | File | 1 | xenograph.dll |
|
Details | File | 1 | gridcloud.dll |
|
Details | File | 1 | 1phoenixhub.dll |
|
Details | File | 1 | xenologic.dll |
|
Details | sha256 | 2 | 6713bfbe1a8dea1ce0b97a5196762fe327f8da770a06e9aff09fff3a4f07cc14 |
|
Details | IPv4 | 8 | 2.9.4.0 |
|
Details | IPv4 | 315 | 8.8.8.8 |
|
Details | Url | 1 | https://www.zscaler.com/blogs/security-research/inside-zloader-s-latest-trick-dns-tunneling |