G-Drive is tapped by a Multistage Malware Downloader
ID: 363ee92e-05a1-5f50-a880-4cef4a421f17
STIX ID: report--363ee92e-05a1-5f50-a880-4cef4a421f17
Feed Name: Zscaler Security Research Blog
**Executive summary:** Zscaler ThreatLabZ analyzed a spam-driven campaign using RTF/XLSM attachments that exploit CVE-2017-8570 to install a highly obfuscated downloader (Win32.Downloader.EdLoader) which employs anti-analysis measures, injects or hollows processes, decrypts XOR-encoded payloads (some hosted on Google Drive), and installs various final payloads including info-stealers and RATs; the report includes technical details and IOCs (hashes) for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
