- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-30-2025 06:59 AM - edited 10-30-2025 07:00 AM
Hi,
We are getting a few alerts for "Evasion Technique - 1244315488" - "Evasion technique using reflective loading."
While investigating I can see that a base64 encoded PE file is written in the registry by taskhosw.exe under "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UCPD\DR\000"
-The registry key is not super well documented (UserChoices Protect Driver)
-The PE, when reconstructed from the base64, is signed by an old Microsoft certificate from 2011.
-Looking on VT for this PE, there is only 1 detection, which does not say much because apparently the file was 1st seen by VT on Oct 27 2025...
I also see in VT that this file have various names which makes me think others found about this activity and submitted the PE to VT for analysis:cyberchef.bin, application.bin, decoded_payload.exe, decoded.exe, output.exe, download.dat, download.exe.malz, download_new.exe, reg-pe.exe.malz
Anyone else observed simillar activity?!
10-30-2025 08:15 AM
Yes we had multiple alerts with the same alert name in the last 2-3 days. I asked TAC and for our case they confirmed a false positive. According to TAC it's a known issue which will be solved within Content Update 2010.
Hope this helps
10-30-2025 08:15 AM
Yes we had multiple alerts with the same alert name in the last 2-3 days. I asked TAC and for our case they confirmed a false positive. According to TAC it's a known issue which will be solved within Content Update 2010.
Hope this helps
10-30-2025 08:17 AM
Yup, this help.
Thanks!
10-31-2025 08:56 PM
Hi all.
highky advising to continue your investigation on the matter , TAC don't deal with investigating and no lighten process wod write an exactable file on the registry , PANW has other service what you can use to verify such thing like u42 or managed hunting , not TAC.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

