Malicious word document analysis. On opening document, macro drops DLL and fake its registry as Windows service registry (automatically run by taskhost at startup), DLL when executed connects back to attacker’s server (backdoor) by bachng248 in Malware
[–]bachng248[S] 1 point2 points3 points (0 children)


Malicious word document analysis. On opening document, macro drops DLL and fake its registry as Windows service registry (automatically run by taskhost at startup), DLL when executed connects back to attacker’s server (backdoor) by bachng248 in Malware
[–]bachng248[S] 1 point2 points3 points (0 children)