PULSE NAME
Crimea manifesto deploys VBA Rat using double attack vectors
WHITE AlienVault 2021-07-30 Modified: 2021-07-30
7
IOCs
LOW VOLUME
On July 21, 2021, Malwarebytes Labs identified a suspicious document named "Manifest.docx" that downloads and executes two templates: one is macro-enabled and the other is an html object that contains an Internet Explorer exploit.
Indicators of Compromise (2 / 7 total)
All CVE FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 03eb08a930bb464837ede77df6c66651d526bab1560e7e6e0e8466ab23856bac 2021-07-30
FileHash-SHA256 fffe061643271155f29ae015bca89100dec6b4b655fe0580aa8c6aee53f34928 2021-07-30