CVE-2017-11882 To Deliver Agent Tesla
ID: 00c951dd-afab-5625-8d1e-a80b6e5de680
STIX ID: report--00c951dd-afab-5625-8d1e-a80b6e5de680
Feed Name: Zscaler Security Research Blog
Threat Score
Executive summary: The report documents a phishing-driven malware campaign that abuses vulnerable Microsoft Excel files to download an obfuscated VBS which retrieves a steganographically embedded Base64 DLL from a JPG; the DLL is decoded and loaded via PowerShell, uses RegAsm process injection to deliver the Agent Tesla infostealer, and exfiltrates stolen browser, mail, FTP credentials and keystrokes to a Telegram bot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
