Fake CAPTCHA Campaign on Arabic Pirated Movie Sites Delivers Lumma Stealer
Tags
country: | Argentina |
attack-pattern: | Dll Side-Loading - T1574.002 Malware - T1587.001 Malware - T1588.001 Powershell - T1059.001 Software - T1592.002 Dll Side-Loading - T1073 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | ba6e49fc-39e3-4c7a-91a2-8814c150020c |
Fingerprint | b06d1f33013f47ea |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Oct. 21, 2024, 7:57 p.m. |
Added to db | Oct. 21, 2024, 10:07 p.m. |
Last updated | Nov. 17, 2024, 6:56 p.m. |
Headline | Fake CAPTCHA Campaign on Arabic Pirated Movie Sites Delivers Lumma Stealer |
Title | Fake CAPTCHA Campaign on Arabic Pirated Movie Sites Delivers Lumma Stealer |
Detected Hints/Tags/Attributes | 35/2/20 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 167 | ✔ | Cybersecurity on Medium | https://medium.com/feed/tag/cybersecurity | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 5 | b-cdn.net |
|
Details | Domain | 1 | filehere0987.b-cdn.net |
|
Details | Domain | 1 | zuni.zip |
|
Details | Domain | 1 | eenoiljq.zip |
|
Details | Domain | 1 | www.forensafe.com |
|
Details | File | 1208 | powershell.exe |
|
Details | File | 1 | zuni.zip |
|
Details | File | 1 | eenoiljq.zip |
|
Details | File | 208 | setup.exe |
|
Details | File | 4 | acrobroker.exe |
|
Details | File | 10 | sqlite.dll |
|
Details | File | 1 | runmrukey.html |
|
Details | File | 17 | attack.exe |
|
Details | sha1 | 1 | 1e5e32c35af6bebeb800083f5c637cb03fac3e37 |
|
Details | sha1 | 1 | bfc1422d1c5351561087bd3e6d82ffbad5221dae |
|
Details | MITRE ATT&CK Techniques | 460 | T1059.001 |
|
Details | Url | 1 | https://filehere0987>.b-cdn.net/zuni.txt |
|
Details | Url | 1 | https://filehere0987.b-cdn.net/zuni.zip |
|
Details | Url | 1 | https://www.forensafe.com/blogs/runmrukey.html |
|
Details | Url | 252 | https://medium.com |