Star Wars bond and

Highly Dangerous sLoad 2.0 (Starsloard) Discovered Malware Recorded by MicrosoftByNovak Bozovic-January 22 2020.1002 The newly discovered strain of malware uses highly sophisticated methods to target Windows Pc while avoiding detection. The Defender Atp Research team at Microsoft is reviewing sLoad and reporting on new versions as soon as they appear online. Microsoft issued a detailed report last month about the newly published app sLoadMicrosoft outlining sLoad 2.0 and its capabilities. Essentially sLoad serves as a delivery system for more robust malware forms. Most specifically, apart from infecting Windows Pcs, it is capable of gathering information about the infected systems and sending the information back to servers of command-and-control (C C). This is when the malware developers will order sLoad to download and install a second payload of malware – which happens as a background process without the user even knowing what’s happening. As such, sLoad can be combined with various types of malware where Retefe Banking Trojan is included in the most recent report. What’s odd about sLoad is that it depends on malicious activities using the Windows Bits (Background Intelligent Transfer Service). This program is mostly used by the Windows Update service which can recognize the usage patterns of your network connection. Differently said Windows Update can see if you do not consciously use your network connection to download updates to Windows without interrupting your workflow. Of course all third parties can use the Windows Bits service. As explained in Microsoft’s article, sLoad creates automatically scheduled tasks of Bits that are executed at regular intervals. This means that sLoad talks to the server for command-and-control and then sends data back to the server and downloads new files. Ironically enough the original sLoad malware could also take screenshots which is a feature not found in the second version. .. 1003 Figure 1 Windows Image Courtesy. The second version of sLoad still uses the operation of Windows Parts, and relies on PowerShell. It did not change its primary purpose-but it made key changes that developed the malware further. During the infection cycle, it now uses Wsf instead of Vb scripts, and it also tests if malware analysts look at the file. Eventually, sLoad 2.0 comes with a system that tracks an infection’s stages (which can be used to monitor or organize sLoad hosts into subgroups). One thing is certain – sLoad 2.0 is a highly sophisticated form of malware that can create a long-lasting impact. The good news, however, is that Microsoft is keeping a close eye on this breed of malware which gives us hope that other vendors will also be able to enforce this information.