Replying to Avatar GHOST

Ok, I received a obvious phishing email with what I can only assume is a malicious pdf attachment.

I took the opportunity to learn from it and opened the file in my home lab isolated VM to examine it.

I suspect it is a key logger with the intent that the person freaks out and logs into their PayPal and Coinbase account.

It has what looks like Java script streams within it and tried to use a Python script to decode it but getting stuck. Any help reading this?

nostr:npub1f6ugxyxkknket3kkdgu4k0fu74vmshawermkj8d06sz6jts9t4kslazcka

#infosec #cybersecurity

Avatar
jpfrogmd 🏴‍☠️⚡️ 2y ago

Got a similar thing recently.

Reply to this note

Please Login to reply.

Discussion

No replies yet.