Posted on 2020-06-08 by William MacArthur
Dridex XLS maldocs with an updated Fancy Image Lure. InQuest Score
Posted on 2020-05-18 by William MacArthur
XLS Zloader Documents still getting 0's "Doughnuts" from AV Detection on VirusTotal: Zloader XLS maldocs with an updated Image Lure has emerged!
Posted on 2020-05-18 by William MacArthur
We wanted to go through and release some of the more interesting examples that we are running into regarding the era of the hidden (very hidden) documents, which we will publish in more flash reports and tweets going forward. .
Posted on 2020-05-12 by William MacArthur
I see some great things happening and people noticing some of the Documents that are going around that have some ties to what I call it as Evloution4 based on the chracteristics we have observed. We are following the evolutions (changes) and other TTPS that we have observed since we started to track heavily.
Posted on 2020-05-11 by William MacArthur
Dridex XLSM Documents using 4.0 Macrosheets and bypassing vendors today. The XLSM 4.0 Macrosheets technique can be further reviewed from our blog post from last week:: ZLoader 4.0 Macrosheets Evolution