New WhiteShadow Downloader Uses MSSQL Servers for Malware Delivery

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,275
A new malware downloader delivered via multiple campaigns uses detection evasion techniques and Microsoft SQL queries to drop malicious payloads onto compromised machines.

The malware, dubbed WhiteShadow by researchers at Proofpoint Threat Insight Team who found it, comes in the form of a set of Microsoft Office macros designed to work together to infect targets with a large array of malware strains it downloads from attacker-controlled Microsoft SQL Servers.

WhiteShadow is delivered via malspam emails containing malicious URLs or Microsoft Word and Microsoft Excel attachments that bundle malicious the downloader's Visual Basic macros which will install the malware payloads after execution.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top