Backswap malware analysis
Tags
country: | Poland |
attack-pattern: | Credentials - T1589.001 Javascript - T1059.007 Malware - T1587.001 Malware - T1588.001 Python - T1059.006 Server - T1583.004 Server - T1584.004 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | bae0d42a-4951-4723-af70-c76f25f08080 |
Fingerprint | 1e07549b8d9517dd |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 19, 2018, midnight |
Added to db | Aug. 31, 2024, 1:44 a.m. |
Last updated | Nov. 17, 2024, 5:58 p.m. |
Headline | Summary |
Title | Backswap malware analysis |
Detected Hints/Tags/Attributes | 36/2/12 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 81 | ✔ | CERT Polska | https://cert.pl/en/rss.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 2 | counter.yadro.ru |
|
Details | Domain | 1 | sexy.com |
|
Details | Domain | 262 | www.welivesecurity.com |
|
Details | File | 1 | %appdata%\mozilla\prefs.js |
|
Details | File | 1 | setclipboarddata.aspx |
|
Details | File | 1 | getwindowlong.aspx |
|
Details | File | 1 | setwindowlong.aspx |
|
Details | File | 1 | sendinput.aspx |
|
Details | File | 748 | kernel32.dll |
|
Details | File | 1 | setwineventhook.aspx |
|
Details | Url | 1 | http://counter.yadro.ru/hit?rhttp://sexy.com/;uhttp://sexy.com |
|
Details | Url | 1 | https://www.welivesecurity.com/2018/05/25/backswap-malware-empty-bank-accounts |