New Ursnif Campaign: From PowerShell to Mshta
ID: 1ce68678-42cc-5031-b193-71d6cdb21d99
STIX ID: report--1ce68678-42cc-5031-b193-71d6cdb21d99
Feed Name: Zscaler Security Research Blog
Threat Score
**Ursnif multistage distribution (Mar 24, 2020):** Zscaler ThreatLabz analyzed a live campaign delivering the Ursnif banking trojan via a three-stage chain (malicious DOC macro -> obfuscated HTA executed by mshta -> index.dll downloaded and executed via regsvr32). The report documents the VBA/HTML/JavaScript payload behavior, decoded payload URL, newly registered domains, payload URLs, a download link and an MD5 hash for the payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
