Phishing Campaigns featuring Ursnif Trojan on the Rise
ID: 39bdb0dd-d457-52d9-93ac-e5c2537accda
STIX ID: report--39bdb0dd-d457-52d9-93ac-e5c2537accda
Feed Name: McAfee Labs Blog
Threat Score
McAfee Labs describes a mass-phishing campaign using malicious Microsoft Word documents with obfuscated VBA macros that extract reversed strings from custom document properties, load and execute shellcode in memory, set an environment variable containing a URL, download an Ursnif DLL to a temporary file, and execute it via rundll32; the report includes static macro analysis, IOCs (file hashes and download URL), detection names, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
