This one is kinda interesting. Uses a .ISO file (Defender and possibly others allowlist by default, but Win10 opens natively), inside there's a .exe which is too large for Defender to scan. C2 is via Apple's push infrastructure. https://www.virustotal.com/gui/file/83f99f42880fcbbbe6e810aa8bc498a4318e27fcfb86301c4bd305be9379234e/detection … https://twitter.com/bcrypt/status/1420471176137113601 …
-
This Tweet is unavailable.Show this thread
Replying to @GossiTheDog
Bart Retweeted Bart
Bart added,
Bart @bartblaze
Replying to @martijn_grooten @BraveSampson @bcrypt
This isn't RedLine, it's another infostealer called ArechClient. Write-up from Trend: https://www.trendmicro.com/en_us/research/21/b/finding-multi-step-obfuscated-malware.html …
It uses RegAsm to load the eventual payload: https://www.virustotal.com/gui/file/059ea6ee0994314502c421d6bab2841593ecaa287538f06a6e2b039fcb95ba6b/detection …
9:25 AM - 30 Jul 2021
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.