2023-02-07 (Tuesday) - Amongst all the #Qakbot malspam, I ran across a #OneNote file pushing unidentified malware. IOCs, #pcap, malware/artifacts, and one of the emails pushing this malware are available at: https://www.malware-traffic-analysis.net/2023/02/07/index.html
There's a history of #Qakbot email distribution used to push other malware like #Matanbuchus (which I originally thought this was) last year and #Squirrelwaffle in September 2021.
But this appears to be a new malware family I haven't seen before.
#qakbot #onenote #pcap #Matanbuchus #SquirrelWaffle
#SquirrelWaffle : quand une campagne de #phishing exploite #ProxyLogon et #ProxyShell !
#SquirrelWaffle #phishing #Proxylogon #proxyshell #securite #microsoftexchange #mails