Malicious PowerPoint Files Constantly Being Distributed - ASEC BLOG
Tags
attack-pattern: | Malware - T1587.001 Malware - T1588.001 Mshta - T1218.005 Powershell - T1059.001 Mshta - T1170 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 6cdb370f-2579-4248-9e99-b1a99f106169 |
Fingerprint | a563bd618df687ee |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Aug. 31, 2021, 11:43 a.m. |
Added to db | Sept. 11, 2022, 4:59 p.m. |
Last updated | Nov. 18, 2024, 1:24 p.m. |
Headline | Malicious PowerPoint Files Constantly Being Distributed |
Title | Malicious PowerPoint Files Constantly Being Distributed - ASEC BLOG |
Detected Hints/Tags/Attributes | 26/1/22 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/26597/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 372 | wscript.shell |
|
Details | Domain | 1 | 92c49223-b37f-4157-904d-daf4679f14d5.usrfiles.com |
|
Details | Domain | 7 | www.bitly.com |
|
Details | Domain | 1 | fckusecurityresearchermotherfkrs.blogspot.com |
|
Details | Domain | 1 | sukmaduck.blogspot.com |
|
Details | Domain | 1 | kukukajadoolunnd.blogspot.com |
|
Details | Domain | 1 | machearkalonikahdi.blogspot.com |
|
Details | Domain | 1 | bukbukbukak.blogspot.com |
|
Details | Domain | 1 | 35d42729-3b2d-44cd-88c7-59a76492301c.usrfiles.com |
|
Details | File | 457 | mshta.exe |
|
Details | File | 1212 | powershell.exe |
|
Details | File | 1 | pdf.ppam |
|
Details | md5 | 1 | 8338e340a6e070805616aee57601706d |
|
Details | md5 | 1 | 5dc1292f5d2e3441e25c4ec6e41d3fa1 |
|
Details | Url | 1 | https://92c49223-b37f-4157-904d-daf4679f14d5.usrfiles.com |
|
Details | Url | 1 | https://www.bitly.com/ddwddwwkfwdwoooi |
|
Details | Url | 1 | https://fckusecurityresearchermotherfkrs.blogspot.com |
|
Details | Url | 1 | https://sukmaduck.blogspot.com |
|
Details | Url | 1 | https://kukukajadoolunnd.blogspot.com |
|
Details | Url | 1 | https://machearkalonikahdi.blogspot.com |
|
Details | Url | 1 | https://bukbukbukak.blogspot.com |
|
Details | Url | 1 | https://35d42729-3b2d-44cd-88c7-59a76492301c.usrfiles.com |