원본 언어로만 콘텐츠 제공
class="post-article">

PSLoaderDLL

PowerShell loader DLL using WMI (process call create) to launch PowerShell with -executionpolicy bypass -nop -w hidden. HTTP multipart POST with macOS Chrome 102 User-Agent camouflage. Fake Origin/Referer: null.jsbin.com. Creates custom .tpp0/.tpp1 files. WebKit form boundary for file uploads.

위협 프로필
유형 Loader
프로그래밍 언어C/C++
C2 프로토콜HTTP
첫 감지2024
대상 Kuresel
목적 / 기능
  • Loader/Dropper
이 패밀리에 대해 아직 확인된 C2 서버가 없습니다.

연구 보고서 (1)

Yüksek

PSLoaderDLL 05c72e77 -- WMI PowerShell bypass nop hidden Execution HTTP Multipart POST macOS Chrome User-Agent null.jsbin.com Fake Origin tpp0 tpp1 Custom Extension | Yuksek

PSLoaderDLL 05c72e77 PE32 DLL x86 413KB. WMI process call create PowerShell -bypass -nop -hidden. HTTP POST multipart macOS Chrome UA. Origin: null.jsbin.com. .tpp0/.tpp1 extensions.

보고서 읽기 →