216.73.217.22

Analyzing the Mekotio Trojan

· Published 30/08/2024 08:14 · Modified 30/08/2024 08:37

Export JSON

Essential information

Published
30/08/2024 08:14
Modified
30/08/2024 08:37
Tags
2024-08-30 malware mekotio trojan obfuscation persistence powershell trojan
Related entities
2 observables, 8 techniques (mitre), 1 malware

Description

The analysis delves into the , a sophisticated that employs a dropper to execute its payload. The dropper employs techniques, such as custom XOR decryption, to conceal its operations. It collects system information, communicates with a command-and-control server for additional payloads, and ensures through system modifications. The main payload consists of executable and script files utilized for malicious activities.

External references