Fake Fedex Email Delivers Donuts!, (Fri, Feb 27th)
ID: 0b24a7ec-e616-566e-a588-2eeb1cbe8f00
STIX ID: report--0b24a7ec-e616-566e-a588-2eeb1cbe8f00
Feed Name: SANS ISC Diary
Threat Score
This write-up analyzes a phishing-delivered Windows batch/PowerShell loader (archive SHA256: a02d54db4ecd6a02f886b522ee78221406aa9a50b92d30b06efb86b9a15781f5) that uses delayed environment expansion, a Base64/AES-encrypted PowerShell payload, persistence via a Run key, and injects decrypted shellcode into explorer; the injected shellcode connects to C2 204.10.160.190:7003 and the behavior is consistent with DonutLoader deploying XWorm.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
