logo

Distribution of DanaBot Malware via Word Files Detected by AhnLab EDR

ID: 4c6efed0-2f28-59ed-860c-433120b484a4

STIX ID: report--4c6efed0-2f28-59ed-860c-433120b484a4

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-05-14

Date Updated: 2026-04-26

Author: ohmintaek

...
...

This report documents a DanaBot campaign distributed through spammed Word documents containing external links that fetch macro-enabled documents; the macros decode and execute CMD/PowerShell commands to download and run DanaBot (iu4t4.exe). EDR telemetry shows the process chain (Outlook → WINWORD.EXE → cmd.exe → PowerShell → rundll32.exe) and behaviors including screenshot capture and credential theft; multiple MD5 indicators and detection names are provided. The report advises caution with attachments and continuous monitoring with security products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.