New Remcos Campaign Distributed Through Fake Shipping Document
ID: 13b66471-f859-5734-975b-c7b2eb16bf0f
STIX ID: report--13b66471-f859-5734-975b-c7b2eb16bf0f
Feed Name: Fortinet Blog
FortiGuard Labs analyzed a phishing campaign distributing a fileless Remcos remote access trojan: a malicious Word document loads a remote RTF that exploits CVE-2017-11882 to run shellcode which downloads and executes a VBScript that launches Base64-encoded PowerShell; the PowerShell loads a disguised .NET module in memory that installs persistence and retrieves a reversed/Base64 Remcos payload, which is injected into a system process via process hollowing. The report includes detailed TTPs, packet and configuration analysis, C2 details (216.9.224.26:51010), URLs, and SHA-256 indicators, and documents Fortinet detections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
