
Downloader Stacks Three Evasion Tricks, Hides C2 in Alibaba DoH Traffic
A trojan tracked as sfuzuan/convagent chains a debugger check, execution stall, and HeavensGate mode switch before resolving command infrastructure through Alibaba's DNS-over-HTTPS service. The technique is far more concretely evidenced than the aging, mostly-dormant domain infrastructure sitting alongside it in the same case.
A downloader carrying the threat label trojan.sfuzuan/convagent packs three separate anti-analysis tricks into a single unsigned Windows binary — a debugger check, a deliberate stall before execution, and a 32-to-64-bit mode transition known as HeavensGate — and then leans on Alibaba's own DNS-over-HTTPS infrastructure to resolve whatever it talks to next.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read