Skip to content

Malware

sLoad

aka Starslord

sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features.

sLoad, also known as Starslord, is a PowerShell malware family.

Background

sLoad is a PowerShell-based downloader whose usual payload is the Ramnit banker, and it stands out for its reconnaissance capabilities. It profiles the infected machine by collecting the list of running processes and checking for Outlook and for Citrix-related files. Beyond that, sLoad can grab screenshots, inspect the DNS cache for particular domains such as targeted banks, and pull down and run external binaries.


Source: Malpedia (Fraunhofer FKIE).