[UPDATE] Here's a #maldoc with (still) live C2 that is quite evasive and shows the detection capability ex-OSINT. Download URL has a "ski" gTLD. Download the sample with a user account (it's not on VT) for free: filescan.io/uploads/636586… // #DFIR #malware #analysis
1
11
24
0
5
Download Image
@filescan_itsec Oh the URL has .ski in it.. never heard of that one.. they really named the file dropped ? 🤨