MSIX With Heavily Obfuscated PowerShell Script, (Fri, Feb 9th)

This post was originally published on this site

A few months ago, we saw waves of MSIX malicious packages[1] dropping malware once installed on victim's computers. I started to hunt for such files and saw a big decrease in interesting hints. Today, my YARA rule triggered a new sample. Called "Rabby-Wallet.msix", the file has a VT score of 8/58[2]

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.