|
|
|
|
|
by firewalkwithme
3323 days ago
|
|
I don't understand how a machine becomes infected, it is perhaps not very clear yet? this article explains receiving an email containing a link OR a PDF with a link to a .hta file ? what a strange sentence. Can one get infected without user interaction, or even with a passive client ? |
|
This malware somehow got seeded, either by (1) direct scanning the internet for vulnerable systems, or (2) traditional "open-this-link / install-this-file" emails/downloads. Maybe that's why we see at least 3 bitcoin addresses: 3 different "seeding" groups.
Corp networks shouldn't be accepting outside SMB connections, and home routers will block them too, so that's where user-initiated emails/downloads come in (or someone connecting an outside laptop).