Threats Tagged 'upx packing'
View all threats tagged with 'upx packing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'upx packing'
Click on any threat for detailed analysis and mitigation recommendations
A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure. Join the discussion | AlienVault OTX General | 08/18/2026, 15:23:42 UTC Added: 08/18/2026, 20:04:25 UTC |
DarkComet RAT malware has resurfaced disguised as a fake Bitcoin-related tool, distributed via a RAR archive containing a UPX-packed executable. Upon execution, it installs itself as 'explorer.exe' in the user's AppData folder and establishes persistence through a registry run key. The malware communicates with its command and control server at kvejo991.ddns.net on port 1604. It performs keylogging, storing captured keystrokes in a dedicated folder, and uses process injection into notepad.exe to evade detection. The malware also spawns multiple cmd.exe and conhost. Join the discussion | AlienVault OTX General | 11/14/2025, 12:09:29 UTC Added: 11/14/2025, 12:31:21 UTC |
Mirai, a notorious botnet targeting IoT devices, has evolved since its 2016 debut. Initially known for massive DDoS attacks, newer variants employ sophisticated techniques like UPX packing and common network utilities for evasion and adaptability. Modern Mirai samples extend beyond DDoS, focusing on data exfiltration and long-term persistence. The analysis compares a June 2025 variant with the original, highlighting differences in execution, network behavior, and file characteristics. The new variant demonstrates increased stealth, modularity, and versatility, making it a more significant threat in the interconnected device landscape. Prevention strategies include updated antivirus software, avoiding suspicious links, and regular system and network monitoring. Join the discussion | AlienVault OTX General | 10/21/2025, 21:49:30 UTC Added: 10/22/2025, 08:21:51 UTC |
Inf0s3c Stealer is a sophisticated Python-based malware designed to collect system information and user data. It systematically gathers host identifiers, CPU information, network configuration, and captures screenshots. The malware enumerates running processes, generates directory views, and compiles stolen data into a password-protected archive for exfiltration. It employs various techniques for persistence, including injection into Discord and Windows Startup manipulation. The stealer targets sensitive information such as passwords, cookies, browsing history, and cryptocurrency wallets. It also implements anti-VM checks and can self-delete after execution. The analysis reveals similarities with other malware projects, suggesting potential for rapid iteration and wider distribution. Join the discussion | AlienVault OTX General | 09/03/2025, 05:35:37 UTC Added: 09/03/2025, 06:17:49 UTC |
Raven Stealer is a modern, lightweight information-stealing malware developed in Delphi and C++. It targets Chromium-based browsers to extract sensitive data, including passwords, cookies, and payment details. The malware uses a modular architecture and UPX packing to evade detection. It executes stealthily and exfiltrates data via Telegram bot integration. Distributed through GitHub and promoted on Telegram, Raven Stealer's user-friendly interface and dynamic module support make it attractive in the commodity malware ecosystem. The malware's capabilities include credential theft, browser data harvesting, and real-time exfiltration, posing a significant threat when used maliciously. Join the discussion | AlienVault OTX General | 07/26/2025, 15:16:39 UTC Added: 07/28/2025, 08:47:35 UTC |
Showing 1 to 5 of 5 results