
KerrDown Loader Disguises DLL as C:\Windows .exe, Splits Sandboxes
A KerrDown-family DLL linked to OceanLotus/APT32 masquerades under an .exe path in C:\Windows and fools two of three sandboxes into a clean verdict. Its C2 domain, cortanasyn.com, serves a TLS certificate borrowed from an unrelated wildcard rather than its own.
A Win32 dynamic-link library carrying the internal path C:\Windows\intkxqhf.exe is, by every technical measure VirusTotal records, not an executable at all — it is a raw PE32 DLL, unsigned, 90 kilobytes, first surfacing on public scanning infrastructure in November 2018 and still being resubmitted as recently as mid-2022. The mismatch between the file's true form and its disguised, exe-shaped alias is not cosmetic.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read