Brushaloader gaining new layers like a pro
ID: 82a3cece-1862-5751-a7ab-d981b7b9fe78
STIX ID: report--82a3cece-1862-5751-a7ab-d981b7b9fe78
Feed Name: CERT Polska
Threat Score
This report analyzes a 2019 Polish-targeted malspam campaign that used a malicious XLS document as a first-stage dropper to deliver Brushaloader, which then deployed an ISFB v2 banking trojan. The author walks through macro extraction, PowerShell deobfuscation, C2 interaction that returns an XOR-encrypted VBScript dropper, and the static config used to download webinjects and redirects for Polish banks and email providers; sample hashes and helper scripts are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
