PULSE NAME
Evoltin POS Malware Attacks via Macro
WHITE AlienVault 2015-06-11 Modified: 2017-08-24
4
IOCs
LOW VOLUME
Over the past couple of months McAfee Labs has seen an increase in the usage of macros to deliver malware. This kind of malware, as mentioned in previous posts (Dridex, Bartallex), usually arrives as an attached document within a phishing email. Recently McAfee labs came across a point-of-sale (POS) malware that spreads through malicious macros inside a doc file. This macro comes into users’ systems through a spam email with subjects such as "My Resume," "Openings," Internship," etc. and an attached Microsoft Word file, some with names like these:
Indicators of Compromise (4)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
domain helpdesk7r.ru 2017-08-24
domain systeminfou48.ru 2017-08-24
domain infofinaciale8h.ru 2017-08-24
FileHash-MD5 6cdd93dcb1c54a4e2b036d2e13b51216 2017-08-24