LinkedIn Job Seeker Phishing Campaign Spreads Agent Tesla

   

LinkedIn Job Seeker Phishing Campaign Spreads Agent Tesla

 

A malicious site that used LinkedIn, a popular professional networking and job search site, as the lure for a social engineering scheme designed to steal a user’s credentials and spread malicious binaries. In addition to the Agent Tesla malware, it also used a custom payload that we have not seen before. The following attributes of the threat actor's infrastructure indicate the focus is LinkedIn users


Indicator Of Compromise

 Email Ids

chanmaestrswiss@yandex.com
mmyoffice@yandex.com
linkedinjob@yandex.com
linkedin.office@yandex.com
m.off1ce@yandex.ru
linkedin.office@yandex.com

File Hashes

f89b4dff6e126e9a5f0a64d590f7b42e
73ee4b60893b0ccc20079882aae66e2f
39648125d1ea711fee091b5ee58eb533
072462810ba6e5a7161b35b8535b55bd
940db8fcba320925e423b44a22e703f1
78d029254cb2350260967feb983d487f
a29a4aea13be816b7929bf103136887d
830bbf1855da3a145831ec55d1c37d17
8cb05c44406adbe13690d816759658da
f4755749ad038edc337c3b23c7b065f5
73ee4b60893b0ccc20079882aae66e2f
072462810ba6e5a7161b35b8535b55bd
940db8fcba320925e423b44a22e703f1
78d029254cb2350260967feb983d487f

URLs\Domain 

linkedlnnetworking.yolasite.com
mpivn.org/LinkedIn-jobs

 

 
 



 

Comments

Popular posts from this blog

Revil Ransomware Targeted Kaseya

BANDOOK(RAT)

Buer Loader provides malware-as-a-service