
Packed svchost.exe Dropper Reveals Tor C2 Inside Sparse APT Feed
A UPX-packed binary posing as svchost.exe is the only richly-documented artifact among 58 file hashes tied to a Donot Team/APT-C-35 indicator set. It shows a full chain from masquerading and anti-debug packing through WMI discovery to Tor-routed command-and-control, while 56 other hashes carry no usable telemetry.
A single UPX-packed binary sitting inside an otherwise thin indicator set shows a strikingly complete tradecraft arc — from disguised execution through anti-analysis packing to discovery and an anonymized command channel — even though the wider record around it barely holds together. The sample, a 7-megabyte Win32 executable that VirusTotal engines label trojan.dekimine, installs itself as %APPDATA%\pwo6\svchost.exe, borrowing the name of a core Windows process while stashing alternate copies…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read