
Word document’s download loop led to executables with different hashes
A recorded PowerShell command defines a download-and-launch loop, while sandbox reports show an executable response, matching artifacts and a launched file. Across reports, the same output pathname held different content, so the recurring filename does not identify a single payload.
A web request in a Word-document sandbox analysis received an HTTP 200 response offering an executable attachment. The same report recorded an artifact under the attachment’s name, identical file content at a different local pathname, and a PowerShell child process bearing that local name. The question is no longer simply whether the document was malicious: how closely can its instructions, network activity and executable output be connected?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read