Remove Cleanup Remove e-Discovery Remove File names Remove Libraries
article thumbnail

A new trojan Lampion targets Portugal

Security Affairs

Looking at the file, it is obfuscated, but in this case, the technique used by criminals was simple: just add commentaries (junk blocks) between the lines of the malicious code to make it confused. After a few rounds of code cleanup (deobfuscation), the final code comes up. At the moment, the file 0.zip amazonaws[.]com/0.zip