Analyzing a Fileless Malware Loader
ID: 417b0db0-5474-515b-b00b-3b9c58461fdb
STIX ID: report--417b0db0-5474-515b-b00b-3b9c58461fdb
Feed Name: WatchGuard Secplicity Blog
WatchGuard Threat Lab analyzed and stopped a sophisticated fileless downloader that executed entirely in memory via JavaScript-triggered PowerShell using ReflectivePEInjection; the attack chain included kernel and Win32k privilege-escalation exploits (CVE-2020-1054, CVE-2019-1458, CVE-2019-0808) and a Chrome sandbox escape (CVE-2019-5786). The report documents domains and MD5s tied to the campaign, explains the in-memory, evasive nature of the attack, and recommends strong EDR/EPP, DNS filtering, and IPS to detect and block similar intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
