Analysis Of SandWorm (CVE-2014-4114) 0-Day
ID: 5445aa2f-9b27-5463-9cb5-9ea061f3ad57
STIX ID: report--5445aa2f-9b27-5463-9cb5-9ea061f3ad57
Feed Name: Zscaler Security Research Blog
**Executive summary:** This report analyzes an in-the-wild zero-day exploit (CVE-2014-4114) delivered via a malicious PowerPoint Slide Show (spiski_deputatov_done.ppsx) that uses embedded OLE objects to retrieve a BlackEnergy executable disguised as a GIF and an INF file (slides.inf) that renames and executes the payload; the campaign is linked to a possible Russian espionage effort targeting NATO, EU, telecommunications, and energy sectors and Zscaler's engines detected and blocked the sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
