Infostealer Malware with Double Extension - SANS Internet Storm Center
Tags
attack-pattern: | Data Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 |
Common Information
Type | Value |
---|---|
UUID | d954014b-da6c-4e81-9990-5c8f4144d460 |
Fingerprint | 798c306b67d2dcc9 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Dec. 18, 2022, midnight |
Added to db | Oct. 24, 2023, 1:33 p.m. |
Last updated | Nov. 17, 2024, 6:30 p.m. |
Headline | Internet Storm Center |
Title | Infostealer Malware with Double Extension - SANS Internet Storm Center |
Detected Hints/Tags/Attributes | 15/1/18 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 129 | api.ipify.org |
|
Details | Domain | 2 | api.ipify.org.herokudns.com |
|
Details | Domain | 2 | mail.reousaomilia.gr |
|
Details | Domain | 2 | reousaomilia.gr |
|
Details | Domain | 3 | www.inkscape.org |
|
Details | Domain | 40 | gchq.github.io |
|
Details | File | 4 | payment_copy.pdf |
|
Details | File | 95 | pdf.exe |
|
Details | sha256 | 2 | 37da8f89540f4dae114f1f55cfd4d89be9582fbd480ac6ed6c34ac04ec8d576b |
|
Details | sha256 | 2 | 3ccaf74f465a79ec320fdb7e44ae09551f4348efd3bf8bf7b3638cc0c1cd8492 |
|
Details | IPv4 | 5 | 3.232.242.170 |
|
Details | IPv4 | 7 | 52.20.78.240 |
|
Details | IPv4 | 3 | 54.91.59.199 |
|
Details | IPv4 | 2 | 65.108.213.43 |
|
Details | IPv4 | 7 | 209.197.3.8 |
|
Details | Url | 2 | https://www.virustotal.com/gui/file/37da8f89540f4dae114f1f55cfd4d89be9582fbd480ac6ed6c34ac04ec8d576b |
|
Details | Url | 2 | https://www.virustotal.com/gui/file/3ccaf74f465a79ec320fdb7e44ae09551f4348efd3bf8bf7b3638cc0c1cd8492 |
|
Details | Url | 27 | https://gchq.github.io/cyberchef |