@solostalking 0683a9750c9c44988c4a8d2b269ad648329caccfc3933efdd972233a70862cd9 Looks like fake cheats downloading the miner (8b43ad177856a521f39ae49614409b0ec84a80c86cb7acff1127f77f103ccfa9)
🧾new report - > "How to target European SMEs with #Ransomware? Through #Zyxel!"
To complete the recent @Truesec and @sekoia_io reports, we link early Sept activities to the #Helldown wave opening many interrogations.
https://t.co/1REmrql0fa
#Malware#QuasarRAT
12cf577a266608862f59fd88331e3622813de09acf0e9ed89f4c19f392c9480d
DLL-Sideloading->Injection to RegAsm.exe->Unzip Calc to C:\Users\Public\Pictures->secur32.dll sideloading by calc.exe->Injection to RegAsm.exe->QuasarRAT
3.94.91.]208
endoftext.]run.]place
Interesting Sample, copies directories and files to %appdata%+Username+'-AntiHeil', zips and uses curl to send the stolen files to a discord webhook. Only 1/2 detections on VT.