Macro targeting Italian companies. Not sure if Trickbot, probably. Interesting to see all HTTPs payloads nowadays, attackers doing some catch up. https://www.virustotal.com/en-gb/file/13c821445f3e789495dcaa85d3c79a5ec8ec73b16cb786482031c8a14c9e5c3c/analysis/ …
-
-
Not that exact one, different payload sites, payload hash etc
End of conversation
New conversation -
-
-
Cheers. I can see it hitting .eu email addresses. Do they usually use HTTPS payload locations?
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.