John Lambert Profile picture
Corporate Vice President, Security Fellow, Microsoft Security Research, johnla(AT)https://t.co/3dGtq71Nby

Jan 31, 2020, 5 tweets

#FFVT Follow Friday on interesting VT Submitter Ids. My first is ec31b410 uploading from Denmark. Examples in this thread

Maldocs that launch code via CreateShortcut and SendKeys
🔗virustotal.com/gui/file/6d630…
🔗virustotal.com/gui/file/65420…

Running unexpected things via manage-bde.wsf and COMSPEC
🔗virustotal.com/gui/file/7493b…
🤜🤛 @bohops

Unicode VBA for obfuscation purposes:
🔗d7987d5bfcd0d8fd206c45b5a83bc429e22759c414d427c8bf1236e7d573f7c3

Amsi bypass by patching memory:
🔗virustotal.com/gui/file/ec559…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling