Blog | G5 Cyber Security

TOPransom: From eMail Attachment to Powning the Attackers Database

A colleague of mine (MarcoT.) gave me an interesting eMail attachment called: 71878378709_708463.zip (sha256:fdd1da3bdd8f37dcc04353913b5b580dadda94ba). By double clicking a.vbs file the victim would run it through microsoft wscript.exe which fires up the infection process. The payload was obfuscated, but the used obfuscation technique was quite weak to reverse. The dropper per-se is not interesting anymore. It basically uses a romantic WScript.Shell to execute a MZ file once downloaded from compromised websites (IoC later on). Dropped file is returned directly into the HTTP response body and saved with a static name.”]

Source: http://securityaffairs.co/wordpress/61575/cyber-crime/topransom-malware.html

Exit mobile version