Colin Cowie · @th3_protoCOL
672 followers · 259 posts · Server infosec.exchange

Continuing with Day 2️⃣​7️⃣: More practice with the VT module, detecting JavaScript malware
🔗 github.com/colincowie/100DaysO

Recently proofpoint shared research about a new threat group they track as that makes use of JavaScript malware:
📖​proofpoint.com/us/blog/threat-

Todays yara rule uses the VirusTotal module to detect JavaScript files that download a .msi sample in the same way TA886's malware does. This rule dug up a lot of low detected samples from this recent campaign!

from retrohunting can be found here:
🔗
github.com/colincowie/100DaysO

#100DaysofYARA #ta886 #iocs

Last updated 2 years ago

securityaffairs · @securityaffairs
416 followers · 322 posts · Server infosec.exchange