An Unlabelled Rust Stealer: A Base64+LZ Codec, Explorer Injection, and Three .website C2s

0. Preface This sample arrived with no family label — just a SHA-256 for a filename and a .exe extension. It turned out to be a two-stage Rust implant: a loader that carries an encoded, headerless DLL, maps it, and injects it into explorer.exe; and the DLL itself, a broad-spectrum infostealer covering Chromium and Gecko browsers, Discord, Roblox, Steam, and cryptocurrency clipboard addresses. Everything below is static analysis. The sample was never executed, no VM was detonated, and none of the recovered domains were contacted....

October 3, 2026 · 15 min

Formbook via RFQ Malspam: A .pdf.js Downloader, a PowerShell Guardian Loop, and aspnet_compiler Hollowing

0. Preface This write-up traces a five-stage chain from an Indonesian-language malspam attachment down to a crypted x86 payload, combining static deobfuscation, an isolated Flare-VM detonation, and a debugger-assisted unpack. The sample arrives as Penawaran RFQ Terlampir 2026.pdf.js — “Penawaran RFQ” is Indonesian for RFQ Quotation, and the double extension is the entire social-engineering play. It is Windows Script Host JavaScript, not a PDF and not browser JS. Four of the five stages are fully characterised: the JS downloader, the XOR PowerShell wrapper, the guardian/injector script, and the ConfuserEx ....

September 25, 2026 · 16 min

Vidar 3.0: A ClickFix verification.vrf Chain with BMP Steganography and 568 Code-Generated Strings

0. Preface This write-up combines two analysis passes on one sample set (vidar-sample/clickfix/): a static + dynamic characterisation of the full ClickFix infection chain, and a deep-dive static analysis of the final payload’s live-decrypted memory image. The first pass answered how the payload arrives; the second answered what it is and what it does — and in doing so upgraded the family identification from “stealer-shaped, unconfirmed” to Vidar 3.0, self-identified, with the entire configuration, 194-API capability surface, and all 568 decrypted strings recovered....

September 18, 2026 · 33 min

BelovaV3: A Fake Game Download, an Electron Shell, and a Bytenode-Wrapped Java Stealer

0. Preface belovav3.pages.dev presents itself as a game download site. The download is BelovaV3.rar; unpacking it yields an NSIS installer, BelovaV3.exe. The installer is 118 MB and the thing it installs is a 177 MB Electron application — a size profile that reads as “big game client” to a victim and does a good job of burying a 13 MB payload. The interesting part of this sample is that almost none of the executable weight is malicious....

September 18, 2026 · 15 min

Domain Parking Malvertising: Analyzing a Suspicious URL from default2024.uk

0. Preface This analysis covers a suspicious URL that triggered an EDR alert when a victim received it via email. The URL https://1.default2024.uk:443 was identified as potentially malicious, and subsequent investigation revealed a domain parking/monetization system with several concerning characteristics. The malicious URL was received through a Gmail account. Email content analysis was out of scope due to privacy restrictions. The URL caused an alert trigger in the EDR system, prompting this investigation....

September 15, 2026 · 11 min

WailsLoader: A Fake PDF Editor, a Homoglyph-Hidden Backdoor, and Microsoft's Own CDN Serving It

0. Preface This set started as 19 MalwareBazaar samples tagged WailsLoader, plus one live capture of the actual drop and its benign installer stub. It ends as six parallel fake-desktop-app campaigns running through the Microsoft Store at once — a PDF editor, an e-signature app, a TOTP authenticator, a task manager, a document signer, and a business tool called AdPayWorks — all built from the same toolkit and fronted by the same distribution mechanism....

September 13, 2026 · 19 min