logo

Malicious Script Delivering More Maliciousness, (Wed, Feb 4th)

ID: c55a9415-24d1-5385-8c03-71f4b78d71c1

STIX ID: report--c55a9415-24d1-5385-8c03-71f4b78d71c1

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-02-04

Date Updated: 2026-04-19

...
...

This report analyzes a malicious email attachment that uses an obfuscated .bat/PowerShell dropper to fetch an innocuous-looking image, extract an embedded Base64 payload, and deploy a .NET XWorm infostealer. The malware establishes persistence via a scheduled task and communicates with its operator through a Telegram bot URL; the write-up provides the decoded sample SHA256, the C2 endpoint, and decoding steps used to recover the binary.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.