Auteur Sujet: [Trend]Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor  (Lu 2928 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor

we found a new sample that may be related to the MuddyWater campaign. Like the previous campaigns, these samples again involve a Microsoft Word document embedded with a malicious macro that is capable of executing PowerShell scripts leading to a backdoor payload. One notable difference in the analyzed samples is that they do not directly download the Visual Basic Script and PowerShell component files, and instead encode all the scripts on the document itself.


The post Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor appeared first on .


Source: Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor

Tags: