VirusTotal += Mandiant Permhash: Unearthing adversary infrastructure and toolkits by leveraging permissions similarity
ID: cb8d3d22-1f16-5c23-b2eb-2b28a6fa0741
STIX ID: report--cb8d3d22-1f16-5c23-b2eb-2b28a6fa0741
Feed Name: VirusTotal Blog
Threat Score
The report analyzes a threat group's distribution infrastructure and modus operandi, using VirusTotal commonalities to identify repeatable patterns (such as .xyz domains and archive.zip filenames), execution parents that drop malicious Chrome extensions, and first-stage artifacts including DMG files and PowerShell scripts; several distribution URLs were observed in the wild and were undetected at the time of writing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
