
Fake Flash Installer Hides PlugX Loader With Timer-Based Sandbox Checks
A Nullsoft-packaged file posing as an Adobe Flash Player update reads the CPU clock and checks for debuggers before dropping its real payload. The stalling installer is the busiest piece in a small PlugX-linked set of three files and two parked domains tied together by shared tradecraft rather than shared infrastructure.
A dropper calling itself install_flash_player.bin does something a real Adobe installer never does: it reads the CPU timer directly to work out whether it is being watched, checks for an attached debugger, and then simply waits — sometimes for long stretches — before it does anything else. Only after that stall completes does the Nullsoft-packaged installer (c56ac01b…) begin dropping its real payload.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read