article thumbnail

SWEED targets precision engineering companies in Italy

Security Affairs

Precision engineering is a very important business market in Europe, it includes developing mechanical equipment for: automotive, railways, heavy industries and military grade technology. The code execution implements a romantic Drop and Execute code by dropping a Windows PE file from: http[://mail.hajj.zeem.sa/wp-admin/edu/educrety.exe

article thumbnail

A month later Gamaredon is still active in Eastern Europe

Security Affairs

During recent times, Gamaredon is targeting the Ukrainian military and law enforcement sectors too, as officially stated by the CERT-UA. The infection chain is composed by different stages of password protected SFX (self extracting archive), each containing vbs or batch scripts. The first file to be executed is “20387.cmd”

article thumbnail

WinRAR CVE-2018-20250 flaw exploited in multiple campaigns

Security Affairs

” Another campaign monitored by FireEye was aimed at the Israeli military, in this case, threat actors used emails with an ACE archive containing documentation for SysAid, a helpdesk service based in Israel. The decoded data starts with the instruction code from the C2 server, followed with additional parameters.”