Source |
Fortinet |
Identifiant |
418006 |
Date de publication |
2017-10-12 12:54:00 (vue: 2017-10-12 12:54:00) |
Titre |
PDF Phishing Leads to Nanocore RAT, Targets French Nationals |
Texte |
Recently, FortiGuard Labs found a phishing campaign targeting French Nationals. In this campaign, a PDF file with an embedded javascript is used to download the payload from a Google Drive shared link. As it turns out, the downloaded file is an HTA (HTML Application) file, a format that is becoming more and more common as a malware launch point. It is usually used as a downloader for the actual binary payload. However in this campaign,... |
Notes |
|
Envoyé |
Oui |
Condensat |
actual application becoming binary campaign common download downloaded downloader drive embedded file format fortiguard found french from google however hta html javascript labs launch leads link malware more nanocore nationals out payload pdf phishing point rat recently shared targeting targets turns used usually |
Tags |
|
Stories |
|
Move |
|