Aria-body loader

Description

(Check Point) The functionality of the Aria-body loader has not changed significantly since 2017, but the implementation varied from version to version. This loader appears to be specifically created for the Aria-body backdoor.

Overall, the loader is responsible for the following tasks:

• Establish persistence via the Startup folder or theRun registry key (some variants). • Inject itself to another process such as rundll32.exe and dllhost.exe (some variants). • Decrypt two blobs: Import Table and the loader configuration. • Utilize a DGA algorithm if required. • Contact the embedded / calculated C&C address in order to retrieve the next stage payload. • Decrypt the received payload DLL (Aria-body backdoor). • Load and execute an exported function of the DLL – calculated using djb2 hashing algorithm.

Names

Name
Aria-body loader

Category

Malware

Type

  • Loader

Information

Malpedia

Other Information

Uuid

5eaa1038-46a4-4d05-8982-25ef7e1cf077

Last Card Change

2022-12-27