MediaArena malvertising: why a quarantine isn’t the end of the incident
ID: 9630bddd-b967-5401-9289-135552ee6d51
STIX ID: report--9630bddd-b967-5401-9289-135552ee6d51
Feed Name: Heimdal Security Blog
Active malvertising campaign distributing BrowserModifier:Win32/MediaArena via fake "AI" recipe apps (GiveMeRecipe, KitchenCanvas, FoodFormula). Installers require no admin rights, drop persistence artefacts to AppData, Start Menu/Startup and an HKCU Uninstall key, and inject the loader (math.dll) in memory; quarantine often occurs after persistence is written. Indicators include kitchen-canvas.com, givemerecipe.com, d3pth7js01bstg.cloudfront.net and sample hashes; investigators should hunt for Startup shortcuts and HKCU Uninstall keys rather than relying solely on file quarantine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
