Empowering Gemini for Malware Analysis with Code Interpreter and Google Threat Intelligence
ID: c582c237-c803-5936-8320-32e9cffef4fb
STIX ID: report--c582c237-c803-5936-8320-32e9cffef4fb
Feed Name: Google Cloud Threat Intelligence
Threat Score
This report analyzes a PowerShell script that implements an RC4-like deobfuscation function (key "tox2") to reveal a URL (https://filedn.eu/lODWTgN8sswHA6Pn8HXWe1J/tox2/Scan_docs%2398097960.msi), downloads the MSI to a temp location, and executes it. The artifact and campaign are attributed to UNC5687 and associated with phishing delivering the MESHAGENT remote access tool; the report includes the deobfuscation code and IOC details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
