Click to Enable Content
ID: 4d028937-9e48-5661-9a1d-04626bc92735
STIX ID: report--4d028937-9e48-5661-9a1d-04626bc92735
Feed Name: Black Hills Infosec Blog
Threat Score
A security research/red-team blog describing a technique for delivering an obfuscated PowerShell backdoor via a macro-enabled PowerPoint (Veil-Evasion + macro_safe.py) that establishes a reverse TCP C2 over port 443; the post demonstrates that common AV and mail scanners did not detect the malicious document and highlights user behavior (clicking through macro warnings) as the primary enabler for successful compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
