# Privateloader

**URL:** https://community.emergingthreats.net/t/privateloader/1226
**Category:** Rule Signatures
**Created:** [December 21, 2023, 11:19pm UTC](https://community.emergingthreats.net/t/privateloader/1226 "2023-12-21T23:19:04Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)
#### Post date: [October 13, 2024, 10:59am UTC](https://community.emergingthreats.net/t/privateloader/1226/5 "2024-10-13T10:59:03Z")

</div>

Hello, Privateloader now has made a radical change update in its network behaviour

New behaviour: [Analysis https://dataprotectioncourse.com/idm+download+with+crack+64+bit+2023.zip Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/103b141b-78cb-4349-afae-7b3b78819075)  
Last tipically privateloader detonation available on me: [Analysis https://dealcatalogue.com/idm+download+with+crack+64+bit+2023.zip Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/be3f3df9-9157-43c6-8313-e09c921fab8d)

new c2s now using port 3306 to communicate between build and c2 host, please see attached detonation focusing on PID 5356 on the new behaviour

There is interaction between c2 and host and then a encrypted string where the configuration is received from c2 host and then the load of malware is done

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/b/b3c981f5c5a0292b95b0ee54170b2a36af208438.png)

Both builds used in detonations were grabbed from the same malvertising ad networks used by InstallsKey PPI service, known for years and should be no problem associating the source of both builds to the same origin

There is no rule detection of this new Privateloader behavior. The old behavior has not been observed since October 5th, some old c2s were destroyed or traditional files inside them were deleted (making them obsolete). So there should be no more questions about associating this new malware behavior to traditional Privateloader builds.

---

_[View the full topic](https://community.emergingthreats.net/t/privateloader/1226)._
