logo

Door-to-Door Worm Cleaner

ID: d7fe993c-52fb-5dd7-a5a4-272dde35e27f

STIX ID: report--d7fe993c-52fb-5dd7-a5a4-272dde35e27f

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A hands-on incident report of a compromised Windows PC reveals an email worm/dropper (MD5 observed) that injected into IE, hooked explorer to capture keystrokes, scanned the local network for new hosts, and POSTed profiling/exfiltration data to .ru command-and-control endpoints; the analyst isolated the host, dumped the malicious process from memory (Postcards.exe) and cleaned the machine using anti-spyware tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.