Covid-19 Variant Malware Evades Secure Email Gateways
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Phishing - T1660 Phishing - T1566 |
Common Information
Type | Value |
---|---|
UUID | ad37bcd1-2043-408e-a455-6e72fb5c52e2 |
Fingerprint | ec95a89939baf78b |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 1, 2021, midnight |
Added to db | Jan. 18, 2023, 9:21 p.m. |
Last updated | Nov. 11, 2024, 6:15 p.m. |
Headline | Covid-19 Variant Malware Evades Multiple SEGs |
Title | Covid-19 Variant Malware Evades Secure Email Gateways |
Detected Hints/Tags/Attributes | 45/2/16 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://cofense.com/blog/covid-19-variant-malware/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | cov19inf.com |
|
Details | Domain | 1 | hgastation.com |
|
Details | Domain | 21 | www.joesandbox.com |
|
Details | Domain | 1 | usergtarca.com |
|
Details | File | 1 | document.xlsm |
|
Details | File | 23 | test.dll |
|
Details | File | 1 | signerlib.xls |
|
Details | md5 | 1 | 0884e793587dc061b8ae69fc086ece83 |
|
Details | md5 | 1 | 2539dbed170613f776445dab9b62fac0 |
|
Details | md5 | 1 | 796b3e4674b68b33c906ce32c3275d83 |
|
Details | sha256 | 1 | bd477b8eabe8baa2042f42b04d6afed2390afc1f3b5f7270538130f96b27e039 |
|
Details | sha256 | 1 | dc8c2d326143ff4334a7bdbafcb821ee9a525eb3248e676e4940baab8d0626a9 |
|
Details | sha256 | 2 | afb5cbe324865253c7a9dcadbe66c66746ea360f0cd184a2f4e1bbf104533ccd |
|
Details | IPv4 | 1 | 172.104.240.67 |
|
Details | IPv4 | 1 | 76.58.124.186 |
|
Details | Url | 1 | https://www.joesandbox.com/analysis/441008/0/html |