Beware of Weaponized TeamViewer Installer that Delivers njRAT
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Keylogging - T1056.001 Keylogging - T1417.001 Malware - T1587.001 Malware - T1588.001 Phishing - T1660 Phishing - T1566 Server - T1583.004 Server - T1584.004 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | b2f88a70-0111-437a-b193-9e7433f63b5a |
Fingerprint | fc2c3f0b29731387 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 14, 2023, 2:25 p.m. |
Added to db | July 14, 2023, 5:59 p.m. |
Last updated | Nov. 15, 2024, 1:55 p.m. |
Headline | Beware of Weaponized TeamViewer Installer that Delivers njRAT |
Title | Beware of Weaponized TeamViewer Installer that Delivers njRAT |
Detected Hints/Tags/Attributes | 30/2/11 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://gbhackers.com/weaponized-teamviewer-delivers-rat/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 163 | ✔ | — | https://media.cert.europa.eu/rss?type=category&id=Malware&language=en&duplicates=false | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 2 | kkk.no-ip.biz |
|
Details | File | 3 | starting.exe |
|
Details | File | 25 | teamviewer.exe |
|
Details | File | 46 | system.exe |
|
Details | md5 | 2 | 11aacb03c7e370d2b78b99efe9a131eb |
|
Details | md5 | 2 | 8ccbb51dbee1d8866924610adb262990 |
|
Details | sha1 | 2 | 9b9539fec7d0227672717e126a9b46cda3315895 |
|
Details | sha1 | 2 | b2f847dce91be5f5ea884d068f5d5a6d9140665c |
|
Details | sha256 | 2 | 224ae485b6e4c1f925fff5d9de1684415670f133f3f8faa5f23914c78148fc31 |
|
Details | sha256 | 2 | 9bcb093f911234d702a80a238cea14121c17f0b27d51bb023768e84c27f1262a |
|
Details | Url | 2 | http://kkk.no-ip.biz |