Custom User-Agent Masquerade
Malware sets an HTTP User-Agent header that mimics a legitimate browser, application, or platform — but with a custom or unusual product name that can serve as a family fingerprint.
Mechanism
Via WinHttpOpen or InternetOpenA, the malware passes a hardcoded User-Agent string. The string may be:
- A near-copy of a real browser UA with one altered token (e.g.,
Chrome/128.0.0.0 Safari/537.36→Chrome/128.0.0.0 Kiosk/1.0). - A completely synthetic UA that follows browser UA syntax but uses a unique product name.
Detection / Fingerprint
- Correlation of unusual product tokens with suspicious hostnames.
User-Agent+X-*custom header clustering across samples.- EDR / proxy logs:
WinHttpOpenwith non-standard UAs from unsigned binaries.