#SappyCache

Malware/Tool

2019-03-26 • WinRAR Zero-day Abused in Multiple Campaigns

SappyCache is FireEye’s name for a previously unknown payload placed in the Windows Startup folder through exploitation of WinRAR. It gathers host and process information, retrieves encrypted command-and-control URLs, and attempts to execute a next-stage payload.

Tagged Reports

« Back