Tag
high
advisory
Lucky Pasta Shellcode Loader for Windows
2 rules 3 TTPs 2 IOCsA shellcode loader dubbed 'Lucky Pasta' employs JIT decryption, string obfuscation, dynamic library loading, fiber-based execution, and AES instruction patching to evade AV detection, retrieving shellcode via HTTP/HTTPS and executing it on Windows systems.
shellcode
windows
jit
defense-evasion
2r
3t
2i
high
threat
TinyCC Masquerading as Svchost for Shellcode Execution
2 rules 2 TTPsAttackers rename TinyCC (tcc.exe) to svchost.exe and use it to compile and execute C source files containing shellcode, using the `-nostdlib` and `-run` flags, as observed in the Lotus Blossom Chrysalis backdoor campaign, indicating potential evasion and malicious code execution.
Tiny C Compiler
Lotus Blossom
tinycc
shellcode
svchost
lotus-blossom
chrysalis
t1059.003
t1027
2r
2t