Evasion Technique - 1244315488

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Evasion Technique - 1244315488

Hi,

We are getting a few alerts for "Evasion Technique - 1244315488" - "Evasion technique using reflective loading."

 

While investigating I can see that a base64 encoded PE file is written in the registry by taskhosw.exe under "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UCPD\DR\000"

 

-The registry key is not super well documented (UserChoices Protect Driver) 

-The PE, when reconstructed from the base64, is signed by an old Microsoft certificate from 2011.

-Looking on VT for this PE, there is only 1 detection, which does not say much because apparently the file was 1st seen by VT on Oct 27 2025...

I also see in VT that this file have various names which makes me think others found about this activity and submitted the PE to VT for analysis:cyberchef.bin, application.bin, decoded_payload.exe, decoded.exe, output.exe, download.dat, download.exe.malz, download_new.exe, reg-pe.exe.malz

Anyone else observed simillar activity?!

1 accepted solution

Accepted Solutions

L3 Networker

Hi @Alexandre_Jodoin 

Yes we had multiple alerts with the same alert name in the last 2-3 days. I asked TAC and for our case they confirmed a false positive. According to TAC it's a known issue which will be solved within Content Update 2010.

Hope this helps

View solution in original post

3 REPLIES 3

L3 Networker

Hi @Alexandre_Jodoin 

Yes we had multiple alerts with the same alert name in the last 2-3 days. I asked TAC and for our case they confirmed a false positive. According to TAC it's a known issue which will be solved within Content Update 2010.

Hope this helps

Yup, this help.

 

Thanks!

L0 Member

Hi all.

highky advising to continue your investigation on the matter , TAC don't deal with investigating and no lighten process wod write an exactable file on the registry , PANW has other service what you can use to verify such thing like u42 or managed hunting , not TAC.

  • 1 accepted solution
  • 387 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!