Tuesday, November 10, 2015

Symantec... how far thou have fallen

An Excel Spreadsheet w/malicious macro (serving as a dropper) is propagating across the Internet this morning. Raytheon|Websense File Sandbox Report found here.

Per the above link, the dropper is pulling an additional executable from Japan (via HTTP) and phoning home on High Numbered TCP Ports to Mother Russia:



Unfortunately, this malware is considered clean by Symantec:


Time to rethink your Security Controls?

No comments:

Post a Comment