Obfuscated WSH dropper with ActiveX
Fallout, this week
What we caught this week while monitoring over 155,936,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
TODAY
Tue Sep 22 · 73 catches · 3 waves · 11 singlesWMI hidden process, persistence, obfuscation
Obfuscated PowerShell download and execution
Obfuscated VBS executes decoded payload
Obfuscated WSH dropper runs PowerShell payload
Obfuscated VBS executes hidden PowerShell
Obfuscated dropper, C2, PowerShell exec
Dependency contains credential stealer
Exfiltrates system data to attacker server
Obfuscated C2 beacon in install hook
Empire C2 framework
Known offensive security toolkit
Clipboard exfiltration, obfuscated C2, wallet theft
YESTERDAY
Mon Sep 21 · 239 catches · 8 waves · 20 singlesMulti-arch botnet dropper
Webshell deployment exploit toolkit
Webshell and WordPress exploit kit
CMS exploit toolkit
Installs hidden RAdmin backdoor services, self-deletes
Process injection and code patching
Downloads and executes remote binaries
Downloads and executes remote exploits
Credential theft, obfuscation, C2 tunnel
Crypto miner with persistence and C2
Obfuscated VBS malware with registry access
obfuscated WhatsApp bot with remote code execution
Exfiltrates Depop auth tokens to ngrok
curl-pipe-sh, credential theft, persistence
Obfuscated credential stealer
Exfiltrates screen captures to Discord
Credential theft, obfuscation, weak passwords
preinstall reverse shell C2