
Loader drops two distinct programs disguised as Windows processes
Sandbox records show a loader dropped two executables named for Windows processes and ran both from temporary directories. Their distinct hashes separate the payloads; other records link one to AppData execution and a matching logon launch setting.
A loader placed two executables named svchost.exe and conhost.exe on disk, and sandbox records show both running from a Windows Error Reporting temporary directory. Their familiar names raise a practical question: were these Windows components participating in an application’s execution, or separate programs borrowing Windows identities? The evidence collected by CTX Threat Intelligence supports the second interpretation.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read