Malware
SodaMaster
aka dfls · HEAVYPOT · DelfsCake
This is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques.
SodaMaster, also known as dfls, HEAVYPOT, DelfsCake, is a Windows malware family operated by Stone Panda.
Background
SodaMaster is a remote access trojan typically delivered through shellcode and/or reflective DLL injection methods. It protects its traffic using RC4 or a hardcoded RSA key, and reaches its operators either over a raw TCP socket or via HTTP POST requests. Some builds also support remote execution of DLLs or shellcode.
Source: Malpedia (Fraunhofer FKIE).