Leave a Reply

3 Comments on "more malware via embedded word macro docs in pdf attachments"

Notify of
avatar
10000
Sort by:   newest | oldest | most voted
Nyebodnye
Guest
Nyebodnye

phinamco.com/f87346b
boaevents.com/f87346b
5hdnnd74fffrottd.com/af/f87346b
byydei74fg43ff4f.net/af/f87346b
https://virustotal.com/en/file/7b0cf85242ab9f32e3d96590464ae291816f660e5ebf1a2c5fff8be35e669b30/analysis/

wipersdirect.com/f87346b
tending.info/f87346b
julian-g.ro/f87346b
https://virustotal.com/en/file/0bf25f6d9e6112129c885173e5992b2928216c8bc2685c17e1148e8573013a09/analysis/

techno-kar.ru/f87346b
babil117.com/f87346b
5hdnnd74fffrottd.com/af/f87346b
byydei74fg43ff4f.net/af/f87346b
https://virustotal.com/en/file/5b7753602e7dcf54c315c2b797d10e7ea11e3c9480f814e20aefa11770669dc5/analysis/

Decryption (xor) key QOfPWKYMzQzNuuzBQGeax2Lkh3Y0oWEl

Payload https://virustotal.com/en/file/0746594fc3e49975d3d94bac8e80c0cdaa96d90ede3b271e6f372f55b20bac2f/analysis/

#Jaff #ransomware

Nyebodnye
Guest
Nyebodnye

trans-atm.com/f87346b
vscard.net/f87346b
5hdnnd74fffrottd.com/af/f87346b
byydei74fg43ff4f.net/af/f87346b
https://virustotal.com/en/file/922a287c4408189722bd10da625f8fde78ed9ac8d76f927b831abbaaf764a0f1/analysis/

trackback

[…] looks like a continuation of last week’s big malspam run that delivered a new ransomware Jaff ransomware but at this time because the online sandboxes haven’t decrypted the encrypted txt file, I have […]

wpDiscuz

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close