Skip to content

Commit

Permalink
Added new malwarebytes reference for Cab File Expansion rule
Browse files Browse the repository at this point in the history
  • Loading branch information
d4rk-d4nph3 committed Aug 31, 2021
1 parent df41805 commit e2bfaea
Showing 1 changed file with 2 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,11 @@ status: experimental
id: 9f107a84-532c-41af-b005-8d12a607639f
author: Bhabesh Raj
date: 2021/07/30
modified: 2021/08/31
description: Adversaries can use the inbuilt expand utility to decompress cab files as seen in recent Iranian MeteorExpress attack
references:
- https://labs.sentinelone.com/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll
- https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/
tags:
- attack.execution
- attack.t1218
Expand Down

0 comments on commit e2bfaea

Please sign in to comment.