#Bumblebee HTML Attachments rolling in.
general pattern: Document_[0-9]{4]_Scan_(Nov8)\.html
Looks like some updated evasion in this sample.
bazaar.abuse.ch/sample/99deeff…
I also looked at an #icedid#bokbot sample from today. The email had an attached .doc file with heavily obfuscated macros.
This infection flow is new to me for #icedid:
.doc -> vba -> embedded .dll dropped and launched
IOCs:
github.com/executemalware…