Russian Dolls VBS Obfuscation, (Fri, Jun 4th)

SANS Internet Storm Center, InfoCON: green 2021-06-04

Summary:

We received an interesting sample from one of our readers (thanks Henry&#;x26;#;x21;) and we like this. If you find something interesting, we are always looking for fresh meat&#;x26;#;x21; Henry&#;x26;#;39;s sample was delivered in a password-protected ZIP archive and the file was a VBS script called "presentation_37142.vbs" (SHA256:2def8f350b1e7fc9a45669bc5f2c6e0679e901aac233eac63550268034942d9f). I uploaded a copy of the file on MalwareBazaar[1].

Link:

https://isc.sans.edu/diary/rss/27494

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

06/04/2021, 08:59

Date published:

06/04/2021, 01:01