Infostealer Malware with Double Extension - SANS Internet Storm Center
Common Information
Type Value
UUID d954014b-da6c-4e81-9990-5c8f4144d460
Fingerprint 798c306b67d2dcc9
Analysis status DONE
Considered CTI value 0
Text language
Published Dec. 18, 2022, midnight
Added to db Oct. 24, 2023, 1:33 p.m.
Last updated Nov. 17, 2024, 6:30 p.m.
Headline Internet Storm Center
Title Infostealer Malware with Double Extension - SANS Internet Storm Center
Detected Hints/Tags/Attributes 15/1/18
Attributes
Details Type #Events CTI Value
Details Domain 129
api.ipify.org
Details Domain 2
api.ipify.org.herokudns.com
Details Domain 2
mail.reousaomilia.gr
Details Domain 2
reousaomilia.gr
Details Domain 3
www.inkscape.org
Details Domain 40
gchq.github.io
Details File 4
payment_copy.pdf
Details File 95
pdf.exe
Details sha256 2
37da8f89540f4dae114f1f55cfd4d89be9582fbd480ac6ed6c34ac04ec8d576b
Details sha256 2
3ccaf74f465a79ec320fdb7e44ae09551f4348efd3bf8bf7b3638cc0c1cd8492
Details IPv4 5
3.232.242.170
Details IPv4 7
52.20.78.240
Details IPv4 3
54.91.59.199
Details IPv4 2
65.108.213.43
Details IPv4 7
209.197.3.8
Details Url 2
https://www.virustotal.com/gui/file/37da8f89540f4dae114f1f55cfd4d89be9582fbd480ac6ed6c34ac04ec8d576b
Details Url 2
https://www.virustotal.com/gui/file/3ccaf74f465a79ec320fdb7e44ae09551f4348efd3bf8bf7b3638cc0c1cd8492
Details Url 27
https://gchq.github.io/cyberchef