Tommy M (TheAnalyst) on Twitter: "Interesting #TrickBot gtag rob139. Obfuscated HTML attachment with encrypted zip with obfuscated js in blob (HTML smuggling). HTML redirects to /abc.com if it doesn't like the browser. JS > PS > EXE. EXE requires vcredist to run. https://t.co/FQBApWcQzj https://t.co/jSuKEhHfNc https://t.co/yamrH9L13C" / Twitter
https://twitter.com/ffforward/status/1462863261335003143