Contenido disponible en idioma original
class="post-article">

XAMLDeserializationDropper

VBScript/VBA macro dropper with XAML ObjectDataProvider deserialization attack. Random-word-combo function name obfuscation (filmbothability, behaviormachineshells). Base64-layered .NET IL bytecode embedded payload. x:Static ConfigurationManager XAML injection.

Perfil de amenaza
Tipo Loader
Lenguaje de programaciónVBScript
Protocolo C2HTTP
Primera detección2023
Objetivos Küresel
Propósito / Capacidades
  • Dropper/Loader
Aún no se han identificado servidores C2 para esta familia.

Informes de investigación (1)

Kritik

XAMLDeserializationDropper -- xABCDEFGHIJKLMNOPQRSTUVWX Rastgele Alfabe İsim Örtüsü, ObjectDataProvider MethodName Set XAML Deserializasyon Payload, filmbothability behaviormachineshells Rastgele Kelime Birleşimi VBScript Fonksiyon Adı Obfuskasyonu, Base64 Katmanlı .NET IL Bytecode Gömülü | Kritik

XAMLDeserializationDropper 237KB ASCII VBScript. xABCDEFGHIJKLMNOPQRSTUVWX rastgele alfabe isim. ObjectDataProvider MethodName=Set XAML deserializasyon. filmbothability behaviormachineshells rastgele kelime VBScript fonksiyon. Base64 .NET IL bytecode.

Leer informe →