Malicious Code Can Be Anywhere, (Tue, Jun 20th)

My Python hunting rules reported some interesting/suspicious files. The files are named with a “.ma” extension. Some of them have very low VT scores. For example, the one with a SHA256 dc16115d165a8692e6f3186afd28694ddf2efe7fd3e673bd90690f2ae7d59136 has a score of 15/59.

Article Link: https://isc.sans.edu/diary/rss/29964