MWLab · Feb 22, 2019
Ursnif campaign with the macro-enabled documents - Part 1
0Sign in to vote or save
This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.
Overview During the first half of February 2019 there was an increase in occurrences of the Spam messages containing attached documents with the names in the form “Request” followed by the number, like “Request15.doc”. These documents contain slightly obfuscated macros which lead to execution of the PowerShell downloader. This PowerShell downloader connects to the domains…

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.