XDLoc

Description

(ESET) XDLoc is a location discovery plug-in that retrieves a list of nearby Wi-Fi access points. It uses the WlanGetNetworkBssListWindows API function to retrieve the list of nearby BSSIDs and their signal strengths (RSSI). This information is then written in <CURRENT_DIRECTORY>\wgl.dat. We believe that this information can be combined with databases of geolocation of known Wi-Fi access points in order to approximate the location of the victim’s device.

Names

Name
XDLoc

Category

Malware

Type

  • Reconnaissance

Information

Other Information

Uuid

7bf7ba03-ce5a-4e89-bc72-da7d6c344370

Last Card Change

2020-10-19