Megalodon malware recently spreading via phishing email campaigns. An Microsoft Excel files is sent which on successful execution download and run a RAT/ key-logger. Megalodon exploits CVE-2017-11882 a excel equation editor vulnerability.
Megalodon XLSX File Signatures
Family: Exploit:O97M/CVE-2017-11882.L
MD5: bdbdcf2548d2e729dab9dde894e1fd43
SHA256: a430bbb3e973487c85dfe4cd5ea1c99684439ba98c3e51e77b845eb8f748dc7c
Megalodon XLSX File Download
Megalodon Payload Signatures
Family: Trojan:MSIL/CryptInject
MD5: c07099852c785bc8009c8b0da8d28358
SHA256: d082c1ec2b496e013563c8192d8cee992c898d5b1b9f9e8e0e4a3505aac1f198
Megalodon Payload Download