Zloader: Entailing Different Office Files

Zloader aka Terdot – a variant of the infamous Zeus banking malware is well known for aggressively using “.xls”, “.xlsx” documents as its initial vector to deliver its payload. Despite this, recently we have come across “.docm” file which is being used by Zoader family to perform its initial activity. This shows adversaries like to […]

Ransomware erupts supporting farmer protests

SARBLOH: A NEW RANSOMWARE THAT DOES NOT DEMAND MONEY

Quick Heal Security Labs came across a Ransomware named “SARBLOH RANSOMWARE”, which claims to support the ongoing farmers protests in the country. In this attack, a malicious document is being spread which downloads ransomware from the following URLs – hxxps://s3.ap-south-1.amazonaws.com/ans[.]video.input/transcode_input/profile16146815778005vw0qb.png hxxp://s3.ap-south-1.amazonaws.com/ans[.]video.input/transcode_input/profile16146815778005vw0qb.png The downloaded ransomware encrypts the files on the system with extension .sarbloh and shows […]