logo

Another day, another malicious JPEG, (Mon, Feb 23rd)

ID: 079bc353-b981-552a-8788-57df45d0fd5d

STIX ID: report--079bc353-b981-552a-8788-57df45d0fd5d

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-02-23

Date Updated: 2026-04-19

...
...

This report analyzes a phishing-driven malware campaign where a large obfuscated JScript attachment (first stage) used Base64 and string obfuscation to spawn a hidden PowerShell process, download a PNG/JPEG containing a Base64-encoded payload, and ultimately retrieve a Remcos RAT binary; the author provides analysis steps, TTPs, and IoCs including URLs and file hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.