MALWARE-OTHER --
MALWARE-OTHER Win.Dropper.PyVil download attempt
This rule detects the attempted download of the PyVil RAT LNK/JavaScript dropper by looking for part of the JavaScript used to stage more of the dropper chain.
This rule detects the attempted download of the PyVil RAT LNK/JavaScript dropper.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Initial Access
Technique: Spearphishing Attachment
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org