logo

Empowering Gemini for Malware Analysis with Code Interpreter and Google Threat Intelligence

ID: c582c237-c803-5936-8320-32e9cffef4fb

STIX ID: report--c582c237-c803-5936-8320-32e9cffef4fb

Feed Name: Google Cloud Threat Intelligence

Threat Score
75/100

Date Published: 2024-11-19

Date Updated: 2026-04-27

Author: Bernardo Quintero

...
...

This report analyzes a PowerShell script that implements an RC4-like deobfuscation function (key "tox2") to reveal a URL (https://filedn.eu/lODWTgN8sswHA6Pn8HXWe1J/tox2/Scan_docs%2398097960.msi), downloads the MSI to a temp location, and executes it. The artifact and campaign are attributed to UNC5687 and associated with phishing delivering the MESHAGENT remote access tool; the report includes the deobfuscation code and IOC details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.