#weaponizeddoc search results

This #WeaponizedDoc powershells down a zip file; extracts it. #InvinceaKilledIt

BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt
BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt

This #TorrentLocker #WeaponizedDoc can't Randomnum. Dont matter. Your users will open anyways.

BelchSpeak's tweet image. This #TorrentLocker #WeaponizedDoc can't Randomnum.  Dont matter.  Your users will open anyways.

This #WeaponizedDoc is titled "Mission Statement" Spoilers: Mission is to Pwn you!

BelchSpeak's tweet image. This #WeaponizedDoc is titled "Mission Statement"
Spoilers:  Mission is to Pwn you!

So Regsvr32 can be used to fetch a file from a URL? wtf.... #WeaponizedDoc @Invincea Kills It. Your AV won't.

BelchSpeak's tweet image. So Regsvr32 can be used to fetch a file from a URL? wtf....
#WeaponizedDoc
@Invincea Kills It.  Your AV won't.

#WeaponizedDoc drops H1N1/Pony by creating 11 cab files. Win95 shipped on 13 cabs. virustotal.com/en/file/93f71c…

BelchSpeak's tweet image. #WeaponizedDoc drops H1N1/Pony by creating 11 cab files.  Win95 shipped on 13 cabs.  
virustotal.com/en/file/93f71c…

Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error. Good ol' Dr. Watson.

BelchSpeak's tweet image. Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error.
Good ol' Dr. Watson.

This #WeaponizedDoc attack- Spreadsheet embedded inside word doc or two attachments? Looks new to me.

BelchSpeak's tweet image. This #WeaponizedDoc attack- Spreadsheet embedded inside word doc or two attachments?  Looks new to me.

Tracking this MemSys #WeaponizedDoc campaign for a while. Uses local DotNet to steal passwords and email contacts.

BelchSpeak's tweet image. Tracking this MemSys #WeaponizedDoc campaign for a while.
Uses local DotNet to steal passwords and email contacts.

Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.

BelchSpeak's tweet image. Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.
BelchSpeak's tweet image. Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.

A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

BelchSpeak's tweet image. A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

I infected myself with a #WeaponizedDoc that delivered #H1N1 just to watch @invincea kill it.

BelchSpeak's tweet image. I infected myself with a #WeaponizedDoc that delivered #H1N1 just to watch @invincea kill it.

This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names. Its (RANDNUM) Your users open it anyways.

BelchSpeak's tweet image. This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names.
Its (RANDNUM)
Your users open it anyways.

This #WeaponizedDoc uses a reservation, not an invoice for lure. 40k+ TCP connections! virustotal.com/en/file/e5fbfd…

BelchSpeak's tweet image. This #WeaponizedDoc uses a reservation, not an invoice for lure.
40k+ TCP connections!

virustotal.com/en/file/e5fbfd…

Hey @malwrhunterteam this #WeaponizedDoc dropped Orcus Ozone Vypr VPN. #RAT Fake Tax Doc Phish @Invincea killed it

BelchSpeak's tweet image. Hey @malwrhunterteam this #WeaponizedDoc dropped Orcus Ozone Vypr VPN.
#RAT
Fake Tax Doc Phish
@Invincea killed it

HR Policies Update #WeaponizedDoc drops #Locky #Ransomware Your workforce will open it. Think your AV will save you?

BelchSpeak's tweet image. HR Policies Update #WeaponizedDoc drops #Locky #Ransomware
Your workforce will open it.
Think your AV will save you?

CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

BThurstonCPTECH's tweet image. CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

Customer gets pounded for no damage by #WeaponizedDoc that powershells to pseudodarkleech p0wnt site. #Cerber? virustotal.com/en/file/aa2583…

BelchSpeak's tweet image. Customer gets pounded for no damage by #WeaponizedDoc that powershells to pseudodarkleech p0wnt site. #Cerber?

virustotal.com/en/file/aa2583…

Absolutley NOT psychological. 😡 Worldwide #coverup by using #psyops on severely injured citizens, utilizing gaslighting & suggestablitiy on the most vulnerable women. Countless, women told it's in "their heads" probably same blokes who still standby hysteria. #WeaponizedDoc

dis_roger's tweet image. Absolutley NOT psychological. 😡
Worldwide #coverup by using #psyops on severely injured citizens, utilizing gaslighting & suggestablitiy on the most  vulnerable women. Countless, women told it's in "their heads" probably same blokes who still standby hysteria. #WeaponizedDoc
dis_roger's tweet image. Absolutley NOT psychological. 😡
Worldwide #coverup by using #psyops on severely injured citizens, utilizing gaslighting & suggestablitiy on the most  vulnerable women. Countless, women told it's in "their heads" probably same blokes who still standby hysteria. #WeaponizedDoc
dis_roger's tweet image. Absolutley NOT psychological. 😡
Worldwide #coverup by using #psyops on severely injured citizens, utilizing gaslighting & suggestablitiy on the most  vulnerable women. Countless, women told it's in "their heads" probably same blokes who still standby hysteria. #WeaponizedDoc
dis_roger's tweet image. Absolutley NOT psychological. 😡
Worldwide #coverup by using #psyops on severely injured citizens, utilizing gaslighting & suggestablitiy on the most  vulnerable women. Countless, women told it's in "their heads" probably same blokes who still standby hysteria. #WeaponizedDoc

CB ThreatSight discovered a #phishing campaign targeting customers via a #WeaponizedDoc. The doc invokes PowerShell w/ obfuscated code to establish netconns & attempts to drop & execute a 2nd stage payload such as #Ursnif ow.ly/CZZN50viwBx @ThreatHuntress @rayrayssi @Jpeg42

carbonb1ack's tweet image. CB ThreatSight discovered a #phishing campaign targeting customers via a #WeaponizedDoc. The doc invokes PowerShell w/ obfuscated code to establish netconns & attempts to drop & execute a 2nd stage payload such as #Ursnif ow.ly/CZZN50viwBx @ThreatHuntress @rayrayssi @Jpeg42

CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

BThurstonCPTECH's tweet image. CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often the #polymorphic banking trojan #Emotet

carbonb1ack's tweet image. CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often the #polymorphic banking trojan #Emotet

CarbonBlack_Inc : Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - …

BThurstonCPTECH's tweet image. CarbonBlack_Inc : Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - …

Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - ow.ly/jXdZ30lBCK7 #infosec @joshpatesec @ThreatHuntress

carbonb1ack's tweet image. Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - ow.ly/jXdZ30lBCK7 #infosec @joshpatesec @ThreatHuntress

So Regsvr32 can be used to fetch a file from a URL? wtf.... #WeaponizedDoc @Invincea Kills It. Your AV won't.

BelchSpeak's tweet image. So Regsvr32 can be used to fetch a file from a URL? wtf....
#WeaponizedDoc
@Invincea Kills It.  Your AV won't.

Customer gets pounded for no damage by #WeaponizedDoc that powershells to pseudodarkleech p0wnt site. #Cerber? virustotal.com/en/file/aa2583…

BelchSpeak's tweet image. Customer gets pounded for no damage by #WeaponizedDoc that powershells to pseudodarkleech p0wnt site. #Cerber?

virustotal.com/en/file/aa2583…

HR Manager puts resumes into folders for open sales positions. SURPRISE! This one is Hancitor #WeaponizedDoc No damage done cuz @Invincea

BelchSpeak's tweet image. HR Manager puts resumes into folders for open sales positions. SURPRISE!  This one is Hancitor #WeaponizedDoc
No damage done cuz @Invincea

#WeaponizedDoc drops H1N1/Pony by creating 11 cab files. Win95 shipped on 13 cabs. virustotal.com/en/file/93f71c…

BelchSpeak's tweet image. #WeaponizedDoc drops H1N1/Pony by creating 11 cab files.  Win95 shipped on 13 cabs.  
virustotal.com/en/file/93f71c…

Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error. Good ol' Dr. Watson.

BelchSpeak's tweet image. Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error.
Good ol' Dr. Watson.

Tracking this MemSys #WeaponizedDoc campaign for a while. Uses local DotNet to steal passwords and email contacts.

BelchSpeak's tweet image. Tracking this MemSys #WeaponizedDoc campaign for a while.
Uses local DotNet to steal passwords and email contacts.

This #TorrentLocker #WeaponizedDoc can't Randomnum. Dont matter. Your users will open anyways.

BelchSpeak's tweet image. This #TorrentLocker #WeaponizedDoc can't Randomnum.  Dont matter.  Your users will open anyways.

Hey @malwrhunterteam this #WeaponizedDoc dropped Orcus Ozone Vypr VPN. #RAT Fake Tax Doc Phish @Invincea killed it

BelchSpeak's tweet image. Hey @malwrhunterteam this #WeaponizedDoc dropped Orcus Ozone Vypr VPN.
#RAT
Fake Tax Doc Phish
@Invincea killed it

This #WeaponizedDoc attack- Spreadsheet embedded inside word doc or two attachments? Looks new to me.

BelchSpeak's tweet image. This #WeaponizedDoc attack- Spreadsheet embedded inside word doc or two attachments?  Looks new to me.

This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names. Its (RANDNUM) Your users open it anyways.

BelchSpeak's tweet image. This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names.
Its (RANDNUM)
Your users open it anyways.

This #WeaponizedDoc powershells down a zip file; extracts it. #InvinceaKilledIt

BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt
BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt

A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

BelchSpeak's tweet image. A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

No results for "#weaponizeddoc"

CB ThreatSight discovered a #phishing campaign targeting customers via a #WeaponizedDoc. The doc invokes PowerShell w/ obfuscated code to establish netconns & attempts to drop & execute a 2nd stage payload such as #Ursnif ow.ly/CZZN50viwBx @ThreatHuntress @rayrayssi @Jpeg42

carbonb1ack's tweet image. CB ThreatSight discovered a #phishing campaign targeting customers via a #WeaponizedDoc. The doc invokes PowerShell w/ obfuscated code to establish netconns & attempts to drop & execute a 2nd stage payload such as #Ursnif ow.ly/CZZN50viwBx @ThreatHuntress @rayrayssi @Jpeg42

Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - ow.ly/jXdZ30lBCK7 #infosec @joshpatesec @ThreatHuntress

carbonb1ack's tweet image. Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - ow.ly/jXdZ30lBCK7 #infosec @joshpatesec @ThreatHuntress

This #WeaponizedDoc powershells down a zip file; extracts it. #InvinceaKilledIt

BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt
BelchSpeak's tweet image. This #WeaponizedDoc powershells down a zip file; extracts it.
#InvinceaKilledIt

This #TorrentLocker #WeaponizedDoc can't Randomnum. Dont matter. Your users will open anyways.

BelchSpeak's tweet image. This #TorrentLocker #WeaponizedDoc can't Randomnum.  Dont matter.  Your users will open anyways.

So Regsvr32 can be used to fetch a file from a URL? wtf.... #WeaponizedDoc @Invincea Kills It. Your AV won't.

BelchSpeak's tweet image. So Regsvr32 can be used to fetch a file from a URL? wtf....
#WeaponizedDoc
@Invincea Kills It.  Your AV won't.

CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often the #polymorphic banking trojan #Emotet

carbonb1ack's tweet image. CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often the #polymorphic banking trojan #Emotet

#WeaponizedDoc drops H1N1/Pony by creating 11 cab files. Win95 shipped on 13 cabs. virustotal.com/en/file/93f71c…

BelchSpeak's tweet image. #WeaponizedDoc drops H1N1/Pony by creating 11 cab files.  Win95 shipped on 13 cabs.  
virustotal.com/en/file/93f71c…

This #WeaponizedDoc is titled "Mission Statement" Spoilers: Mission is to Pwn you!

BelchSpeak's tweet image. This #WeaponizedDoc is titled "Mission Statement"
Spoilers:  Mission is to Pwn you!

This #WeaponizedDoc uses a reservation, not an invoice for lure. 40k+ TCP connections! virustotal.com/en/file/e5fbfd…

BelchSpeak's tweet image. This #WeaponizedDoc uses a reservation, not an invoice for lure.
40k+ TCP connections!

virustotal.com/en/file/e5fbfd…

Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error. Good ol' Dr. Watson.

BelchSpeak's tweet image. Some victims are able to dodge a #WeaponizedDoc and its payload due to a fatal error.
Good ol' Dr. Watson.

CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

BThurstonCPTECH's tweet image. CarbonBlack_Inc : CB ThreatSight recently discovered a widespread #phishing campaign targeting customers via a #WeaponizedDoc which invokes PowerShell w/ obfuscated code to establish netconns and attempts to drop and execute a 2nd stage payload, often th…

A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

BelchSpeak's tweet image. A #WeaponizedDoc uses bitsadmin to download malware named with a political message about the Jews.

Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.

BelchSpeak's tweet image. Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.
BelchSpeak's tweet image. Latest H1N1 #WeaponizedDoc dropper has strings of "talking corrosive fledgling LILO.

This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names. Its (RANDNUM) Your users open it anyways.

BelchSpeak's tweet image. This #Locky spammer spent July 4th Fat Fingering his #WeaponizedDoc names.
Its (RANDNUM)
Your users open it anyways.

HR Policies Update #WeaponizedDoc drops #Locky #Ransomware Your workforce will open it. Think your AV will save you?

BelchSpeak's tweet image. HR Policies Update #WeaponizedDoc drops #Locky #Ransomware
Your workforce will open it.
Think your AV will save you?

Tracking this MemSys #WeaponizedDoc campaign for a while. Uses local DotNet to steal passwords and email contacts.

BelchSpeak's tweet image. Tracking this MemSys #WeaponizedDoc campaign for a while.
Uses local DotNet to steal passwords and email contacts.

CarbonBlack_Inc : Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - …

BThurstonCPTECH's tweet image. CarbonBlack_Inc : Cb #ThreatSight has investigated a wide #phishing campaign targeting customers via a #WeaponizedDoc - invokes #CMD and #PowerShell w/ obfuscated code, establishes net conns, attempts to drop/execute a 2nd stg payload - …

Loading...

Something went wrong.


Something went wrong.


United States Trends