ELISE: Security Through Obesity - Cyber security updates
ID: 78944fa0-122f-406d-94b6-b582e6e304a3
STIX ID: report--78944fa0-122f-406d-94b6-b582e6e304a3
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-01-06
Last Modified Date: 2016-01-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC blog analyzes a targeted espionage malware campaign against Taiwanese users: a malicious PowerPoint exploiting CVE-2014-4114 drops a DLL payload (hlwyss.dll/Syncmgr.dll), injects into iexplore.exe, loads a heavily padded 500+MB DAT component likely used to evade AV, and communicates with dynamic DNS C2 hosts (e.g., ustar5.PassAs.us). The report provides behavioral details, file and network IOCs (MD5s, domains, IPs), YARA signatures, and attributes the activity to the Lotus Blossom actor based on language, tooling and configuration similarities.
