GUloader Unmasked: Decrypting the Threat of Malicious SVG Files
ID: 603d8197-c38c-561d-a137-e5fcc38873fb
STIX ID: report--603d8197-c38c-561d-a137-e5fcc38873fb
Feed Name: McAfee Labs Blog
Threat Score
McAfee Labs analysis describes a GUloader campaign distributed through malicious SVG attachments that use embedded JavaScript to drop a ZIP containing an obfuscated WSF; the WSF launches PowerShell to fetch base64-encoded payloads from a remote URL, decode shellcode, and perform process hollowing into MSBuild for execution and persistence, with indicators (SHA256 hashes and URL) provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
