logo

Image or Malware? Read until the end and answer in comments :)

ID: c425fded-cbed-5b67-979e-7caac85e1582

STIX ID: report--c425fded-cbed-5b67-979e-7caac85e1582

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Executive summary: The report analyzes a malicious email-delivered .cmd dropper (downloaded from a shortened URL) that requests elevation, adds Defender exclusions for its installation folder and final executable, fetches a disguised payload (jpg→zip→exe), extracts and renames the payload, creates a hidden scheduled task for persistence, forces a reboot, and self-deletes. The author supplies decoded script fragments, static analysis observations of the extracted DLL/binary, screenshots of the delivery and extraction process, and references to IoCs discovered during the investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.