A research that covers the structural aspects of CPL files & how criminals are using it to spread malware in Brazil:http://bit.ly/1f6DoU3
-
-
Replying to @TrendMicroRSRCH
@TrendLabs@MenteBinaria this is not limited to ZIP files & Brazil, also seen CPL in RTF in Switzerland (in German) https://www.virustotal.com/en/file/28e08c2174e341cca03662b31aaa540780cb8e39e7e309164a61c4a8d6244b72/analysis/1390838824/ …2 replies 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure@TrendLabs We've seen that in Brazil toohttp://blog.trendmicro.com/trendlabs-security-intelligence/control-panel-files-used-as-malicious-attachments/ …1 reply 1 retweet 2 likes -
Replying to @mer0x36
@MenteBinaria@TrendLabs seen some w/ DarkKomet & TROJ_FORUCON.BMC detections. Is that really DarkKomet or some RAT? https://www.virustotal.com/en/file/28e08c2174e341cca03662b31aaa540780cb8e39e7e309164a61c4a8d6244b72/analysis/1390997554/ …1 reply 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure Hi there! We'll check with our experts on this and get back to you as soon as we can.@MenteBinaria1 reply 0 retweets 0 likes -
Replying to @TrendMicroRSRCH
.
@c_APT_ure. Looks like it's neither -- It's an RTF file (TROJ_ARTIEF.KVV) with a ZBOT attachment (TSPY_ZBOT.KVV)@MenteBinaria3 replies 2 retweets 2 likes -
Replying to @TrendMicroRSRCH
AV vendors, please add detections for this
#malware (VT: 0/50 !!) https://www.virustotal.com/en/file/b2a9535172885f57a77cfe46deab3b0394837d90418f2ee3cf2592c01687e159/analysis/1391525864/ … (again CPL in RTF) /CC@TrendLabs@MenteBinaria3 replies 4 retweets 4 likes -
Replying to @c_APT_ure
4 RTF & CPL
#malware samples with VT 0/50 !! https://www.virustotal.com/en/file/f5dd6893af7755f0df559ebaefc59faa23ea1b6699cf0c900200ffcd3d3f1a78/analysis/1391530810/ … https://www.virustotal.com/en/file/c682939e04b8ac1a78adee8da77f4815b6c5216e353512e8a7495b205e50010b/analysis/1391530841/ … https://www.virustotal.com/en/file/329519d408a90b4f5e5d40ec7803364e52481ee5df0d1b6e64c6409858120123/analysis/1391530910/ … https://www.virustotal.com/en/file/b2a9535172885f57a77cfe46deab3b0394837d90418f2ee3cf2592c01687e159/analysis/1391530952/ …2 replies 2 retweets 0 likes
@c_APT_ure Thanks Tom, I'll check it out.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.