Skip to content

Malware

HOTWAX

HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file.

HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.


Family metadata imported from Malpedia (Fraunhofer FKIE).