Malicious RTF Documents Spreading Malware
ID: 94b631d6-1e40-54d4-8a03-e0e7f81a7c1e
STIX ID: report--94b631d6-1e40-54d4-8a03-e0e7f81a7c1e
Feed Name: Zscaler Security Research Blog
Malicious RTF documents embed multiple Excel OLE objects and use the \objupdate control to force repeated macro prompts and execution; embedded VBA runs PowerShell to drop a VBS (svchost32.vbs) which downloads and executes svchost.exe, resulting in NetWiredRC and Quasar RAT infections. The macro also modifies registry keys to permanently enable Office macros. The report includes deobfuscated macro/VBS/PowerShell details, infection flow, and IOCs (MD5 hashes, download URLs, C2 domains/IPs) tracked by Zscaler ThreatLabZ.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
