Distribution of RAT Malware Disguised as a Gambling-related File
ID: 112ee899-b3f0-5701-9dd5-40c621afac3c
STIX ID: report--112ee899-b3f0-5701-9dd5-40c621afac3c
Feed Name: ASEC
Threat Score
The report documents a malicious campaign where threat actors use shortcut/HTA files and obfuscated VBS/PowerShell to download decoy Excel documents (percent.xlsm) and payloads (darkss.exe — Venom RAT, Pandora_cryptered.exe — Pandora hVNC). It provides active indicators including C2 addresses (e.g., 193.***.***.253:4449, 85.209.176.158:7287), URLs, MD5 hashes, detection names, and shows the malware performs credential/keylogging theft and remote control activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
