#SideWinder #APT
Notification No. MoDP 4346. zip (MoDP: Ministry of Defence Production of Pakistan)
490aeba4e2034bb7ff45ad22ffaaae42
It contains a maldoc and a decoy pdf:
Maldoc: (It seems it is an old sample of this threat actor. Creation time: 2017-10-27)
Officers order.docx
cab6916c5829a8bb7fd9c66dca177992
It uses DDE to calls Mshta to download the next stage.
en-db.herokuapp[.]com
Decoy pdf:
DOC-20221211-WA0093.pdf
ce9d11cfff7ae6fd2b063ce69de2ac5d

