CoreLoader

Description

(Kaspersky) CoreLoader, the last malware we found associated to this set of activity, is a simple shellcode loader which performs anti-analysis and loads additional code from a file named WsmRes.xsl. Again, this specific file eluded our attempts to catch it but we suspect it to be, one way or another, related to FoundCore (described in the previous section).

Names

Name
CoreLoader

Category

Malware

Type

  • Loader

Information

Other Information

Uuid

904bb94c-6e68-43a6-913a-ce026f9de390

Last Card Change

2021-05-15