Detecting Multi-Stage Infection Chains Madness
ID: a712b3f5-9488-50c5-8583-eb217679ad99
STIX ID: report--a712b3f5-9488-50c5-8583-eb217679ad99
Feed Name: Sekoia.com
Threat Score
This report details a multi-stage malware campaign (observed since Feb 2024) that leverages Cloudflare tunnel WebDAV hosting to distribute remote access trojans (notably AsyncRAT) via phishing (.ms-library attachments) and a complex LNK->HTA->BAT->Python->DLL execution chain; it includes detection guidance (Sigma/SOL rules), persistence and defense-evasion behaviors, and actionable IoCs (trycloudflare/duckdns domains and file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
