CyberRaiju @jaiminton.com · Jun 24

New Octowave Loader sample is leading to Amatera Stealer deployment over the past week. 0 VT detections on any component of the malware loader. Proofpoint rules detect the outbound C2 traffic. My Yara rule detects the installer.

6 likes 2 replies

?

Replies

CyberRaiju · Jun 24

Adobe printer driver sideloads tbb.dll, tbb.dll loads app-2.3.dll which gets stego from blood.wav, uses zxing.presentation.dll and Xceed.Wpf.AvalonDock.Themes.Aero.dll MSI: www.virustotal.com/gui/file/f5c... Components all with 0 VT detections. DLLs are legitimate ones that were modified.

Tiesun · Jul 3

Vamos 🤌 captain