Microsoft Vulnerability Leads to RAT & Phishing Site
ID: 5395fbd8-c114-55bd-8f76-55d84ea123ac
STIX ID: report--5395fbd8-c114-55bd-8f76-55d84ea123ac
Feed Name: Zscaler Security Research Blog
This report describes a phishing campaign delivering malware via a password-protected ZIP attachment containing an RTF weaponized with CVE-2017-11882. The RTF drops an HTA (note.hta) that runs VBScript and a hidden PowerShell process to download and execute clear.exe (a Python-converted RAT) which connects to a C2 (197.200.145.178:2016). The campaign also uses AES-encrypted phishing webpages that decrypt in-browser to evade crawlers and collect sensitive information. The document includes IoCs, RAT command capabilities, examples of phishing lure content, and Zscaler/Microsoft mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
