Spammers Smuggle LokiBot Via URL Obfuscation Tactic
#1
Information 
Quote:Spammers have started using a tricky URL obfuscation technique that sidesteps detection – and ultimately infects victims with the LokiBot trojan.
 
The tactic was uncovered in recent spear-phishing emails with PowerPoint attachments, which contain a malicious macro. When the PowerPoint file is opened, the document attempts to access a URL via a Windows binary (mshta.exe), and this leads to various malware being installed onto the system.
 
This process is not unusual for macro downloaders. However, because the domains associated with the campaign are already known to host malicious files and data, the attackers used a unique semantic attack on the campaign’s URLs to trick the email recipient and avoid being flagged by email and AV scanners. A semantic URL attack is when a client manually adjusts the parameters of its request by maintaining the URL’s syntax – but altering its semantic meaning. More on that, below.

“We found it interesting that the attackers were using URIs in this way, which essentially is an attack on the user’s preconceived notion of what a URI should look like,” said researchers with Trustwave in a Thursday report. “It may also defeat security solutions, which may be expecting URIs in a certain format.”

Read more: https://threatpost.com/lokibot-url-obfuscation/159729/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Malwarebytes 5.2.11.183
Malwarebytes 5.2.1...Mohammad.Poorya — 16:44
CCleaner 6.35.11488 (16 Apr 2025)
CCleaner 6.35.1148...harlan4096 — 07:24
Brave 1.77.100
Release Channel 1....harlan4096 — 07:22
Tor Browser 14.5
Tor Browser 14.5​ ...harlan4096 — 07:22
Vivaldi 7.3 Build 3635.11
Vivaldi 7.3 Build ...harlan4096 — 07:20

[-]
Birthdays
Today's Birthdays
avatar (48)oapedDow
avatar (41)Sanchowogy
Upcoming Birthdays
avatar (44)wapedDow
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (37)RobertUtelt

[-]
Online Staff
mjcn19's profile mjcn19

>