About

Tuesday, March 31, 2020

Beware of scam during COVID-19 Pandemic:

We are all in the mid of pandemic on the Corona infection widespread and facing nationwide lockdown (many countries are facing the lockdown for more than 15 days. Many people including celebrities like actors, sportspersons started contributing to generously on PM care fund, so these funds can contribute to people who are suffering from COVID-19 infection. But, scammers are using this time to lure the contributor and collecting funds to fake BHIM account which deceives like PMcare fund. Refer to the below snapshot:

The legit account has the beneficiary name (Registered name) as Pm Cares and the fake ID as pmcare@sbi. Contributors need to be more careful about the beneficiary BHIM UPI ID is correct. Ev 


Post by

Saturday, March 7, 2020

Analysis of latest Trickbot malware sample - served in excel attachment

Twitter link:

The malware sample of trickbot was already submitted in the anyrun online sandbox for malware analysis.




We collected this malware sample and performed a manual analysis. The file details are:


Searched this hash in the VirusTotal for detection hits:


File name: Unpaid_invoice_1462.xls

File size: 109.5 KB
SHA256: 9e777e1e2e80909b5054c1eca935edc7046feb7d4546f40d392549e2f481d08e
MD5: 1f38f17810621dbff93a4e8cbd2ea1bf

This excel embedded with a macro that connects to a suspicious URL. We executed the malware in our VM, it prompts to enable the macro. After enabling, it to try to connect the following Link:

URL: pnxkntdl(.)xyz/KJSDBViad7

Currently, it didn’t download any other payloads.



Post made by

fast16 & The MARINTEK False Positive | Threat Intelligence

fast16 & The MARINTEK False Positive | Threat Intelligence THREAT//INTEL APT Analysis Reverse Engineering False Positive W...