Distribution of DanaBot Malware via Word Files Detected by AhnLab EDR
ID: 4c6efed0-2f28-59ed-860c-433120b484a4
STIX ID: report--4c6efed0-2f28-59ed-860c-433120b484a4
Feed Name: ASEC
This report documents a DanaBot campaign distributed through spammed Word documents containing external links that fetch macro-enabled documents; the macros decode and execute CMD/PowerShell commands to download and run DanaBot (iu4t4.exe). EDR telemetry shows the process chain (Outlook → WINWORD.EXE → cmd.exe → PowerShell → rundll32.exe) and behaviors including screenshot capture and credential theft; multiple MD5 indicators and detection names are provided. The report advises caution with attachments and continuous monitoring with security products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
