Door-to-Door Worm Cleaner
ID: d7fe993c-52fb-5dd7-a5a4-272dde35e27f
STIX ID: report--d7fe993c-52fb-5dd7-a5a4-272dde35e27f
Feed Name: Zscaler Security Research Blog
Threat Score
A hands-on incident report of a compromised Windows PC reveals an email worm/dropper (MD5 observed) that injected into IE, hooked explorer to capture keystrokes, scanned the local network for new hosts, and POSTed profiling/exfiltration data to .ru command-and-control endpoints; the analyst isolated the host, dumped the malicious process from memory (Postcards.exe) and cleaned the machine using anti-spyware tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
