Malicious Outlook Rule without an EXE
ID: 6da23064-435a-5180-8bf8-350d3813d975
STIX ID: report--6da23064-435a-5180-8bf8-350d3813d975
Feed Name: Black Hills Infosec Blog
Threat Score
This write-up demonstrates an email-based technique to achieve remote code execution and C2 by leveraging Outlook rules to download and execute a VBE file that runs an encoded PowerShell Meterpreter reverse shell. The author details bypassing EXE download restrictions, AV detection of an autogenerated VBS payload, and a manually crafted VBScript that successfully launches a hidden PowerShell session to connect to an attacker-controlled server.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
