Coronavirus-Themed Document Targets Brazilian Users
ID: 71f8c010-8a9c-5eaf-a999-4942d193b166
STIX ID: report--71f8c010-8a9c-5eaf-a999-4942d193b166
Feed Name: Zscaler Security Research Blog
Threat Score
Technical analysis of a COVID-19 themed macro-based PowerPoint (PPS) observed in the wild that downloads an HTA which, after a timed delay, reverses and decodes a Base64 blob stored in the registry and uses PowerShell to load a .NET njRAT assembly. The report includes file hashes, C2 hostname and port, registry keys, mutex and other IoCs, and describes njRAT behaviors including information collection, keylogging, persistence and communication with the attacker C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
