logo

ELISE: Security Through Obesity - Cyber security updates

ID: 78944fa0-122f-406d-94b6-b582e6e304a3

STIX ID: report--78944fa0-122f-406d-94b6-b582e6e304a3

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-01-06

Last Modified Date: 2016-01-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC blog analyzes a targeted espionage malware campaign against Taiwanese users: a malicious PowerPoint exploiting CVE-2014-4114 drops a DLL payload (hlwyss.dll/Syncmgr.dll), injects into iexplore.exe, loads a heavily padded 500+MB DAT component likely used to evade AV, and communicates with dynamic DNS C2 hosts (e.g., ustar5.PassAs.us). The report provides behavioral details, file and network IOCs (MD5s, domains, IPs), YARA signatures, and attributes the activity to the Lotus Blossom actor based on language, tooling and configuration similarities.