
Two Unrelated Trojans Share One Crypter's XOR Fingerprint
A CMSTP-based UAC-bypass stealer and an lsass.exe-masquerading dropper carry different VirusTotal labels and mismatched imphashes, yet both trip the same Mozilla/5.0 XOR-obfuscation rule and share a compile timestamp. The overlap points to a shared crypter or builder stage, not a shared malware family.
Two brand-new payloads dropped into this snapshot's file cohort are not, on paper, the same malware. VirusTotal's own labels split them cleanly — one reads trojan.stealer/bypassuac, the other trojan.phil/mint — and neither carries a matching imphash. Yet a UAC-bypass stealer identified by the crowdsourced YARA rule INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM (8cf4ae00be0fe987cc14ae74b0b64c188083b8bbe3b7397239cefd594492c6cd) and a second binary masquerading as core Windows processes both fire a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read