11-29-2025, 04:16 PM
Behavior: Keylogging, reverse proxy, persistence.
SHA256:
Mitigation:
SHA256:
Code:
951ebdcb8ff094723fd778bba84c07e90f804c0c9ee127dc08d9e6fabc7f5db0- EDR: detect keylogging hooks.
- Quarantine droppers.
- Firewall blocklist for RAT C2s.
