Multiple Malware Dropped Through MSI Package, (Wed, Aug 14th)

SANS Internet Storm Center, InfoCON: green 2024-08-14

Summary:

One of my hunting rules hit on potentially malicious PowerShell code. The file was an MSI package (not an MSIX, these are well-known to execute malicious scripts[1]). This file was a good old OLE package:

Link:

https://isc.sans.edu/diary/rss/31168

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

08/14/2024, 08:25

Date published:

08/14/2024, 04:15