Iranian #Greenbug targeting against Arab Emirates - filename was "Invoice-NO48935.doc".
— ClearSky Cyber Security (@ClearskySec) February 6, 2018
Uses IPv6 DNS requests for communication to command and control server acrobatverify\.com
Further Analysis in "Raw Threat Intelligence": https://t.co/NAAOcN3y5G pic.twitter.com/894yyEdPeO
https://t.co/NAAOcN3y5G from Twitter https://twitter.com/ClearskySec