From South America to Southeast Asia: The Fragile Web of REF7707

While the REF7707 campaign is characterized by a well-engineered, highly capable, novel intrusion set, the campaign owners exhibited poor campaign management and inconsistent evasion practices. Author: AlienVault

Related Tags:
scheduled task

lolbin

lolbas

typo squatting

siestagraph

southeast asia

guidloader

GUILOADER

ref7707

Associated Indicators:
9A11D6FCF76583F7F70FF55297FB550FED774B61F35EE2EDD95CF6F959853BCF

83406905710E52F6AF35B4B3C27549A12C28A628C492429D3A411FDB2D28CC8C

39E85DE1B1121DC38A33ECA97C41DBD9210124162C6D669D28480C833E059530

D9FC1CAB72D857B1E4852D414862ED8EAB1D42960C1FD643985D352C148A6461

6D79DFB00DA88BB20770FFAD636C884BAD515DEF4F8E97E9A9D61473297617E3

08331F33D196CED23BB568689C950B39FF7734B7461D9501C404E2B1DC298CC1

49E383AB6D092BA40E12A255E37BA7997F26239F82BEBCD28EFAA428254D30E1

7CD14D3E564A68434E3B705DB41BDDEB51DBB7D5425FD901C5EC904DBB7B6AF0

20508EDAC0CA872B7977D1D2B04425AAA999ECF0B8D362C0400ABB58BD686F92