My honeypot captured several copies of this file info.zip (info.vbe). I used Didier’s Python script decode-vbe.py to examine the file and obtained following output:
Article Link: https://isc.sans.edu/diary/rss/23036
My honeypot captured several copies of this file info.zip (info.vbe). I used Didier’s Python script decode-vbe.py to examine the file and obtained following output:
Article Link: https://isc.sans.edu/diary/rss/23036