216.73.217.22

More Steganography!

· Published 14/06/2025 16:52 · Modified 16/06/2025 14:54

Export JSON

Essential information

Published
14/06/2025 16:52
Modified
16/06/2025 14:54
Tags
2025-06-14 base64 dll excel hta katz stealer powershell steganography vbs
Related entities
9 techniques (mitre), 1 malware

Description

A malicious file using was analyzed, revealing embedded XLS sheets and a complex infection chain. The file downloads an file that creates a BAT file, which in turn generates and executes a file. The file fetches a VBA script that creates and runs a script. The script downloads an image containing a hidden payload delimited by specific tags. The payload is a -encoded PE file, which is decoded and executed as a . The final payload appears to be a . This analysis highlights the use of multiple file types and techniques to evade detection.

External references