IcedID Circulates Via Web Forms, Google URLs
#1
Information 
Quote:Website contact forms and Google URLs are being used to spread the IcedID trojan, according to researchers at Microsoft.
 
Attackers are using “contact us” forms on websites to send emails targeting organizations with trumped-up legal threats, researchers said. The messages consistently mention a copyright infringement by a photographer, illustrator or designer, and they contain a link to purported “evidence” for these legal infractions. But the link in actuality leads to a Google page that downloads IcedID (a.k.a. BokBot), which is an information-stealer and loader for other malware.
 
“As attackers fill out and submit the web-based form, an email message is generated to the associated contact-form recipient or targeted enterprise, containing the attacker-generated message,” according to Microsoft’s recent posting. “The message uses strong and urgent language (‘Download it right now and check this out for yourself’), and pressures the recipient to act immediately, ultimately compelling recipients to click the links to avoid supposed legal action.”

Read more: IcedID Circulates Via Web Forms, Google URLs | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.5  Disabled ...Kool — 10:15
Hasleo software (formerly called EasyUE...
Hasleo Backup Suite ...jasonX — 21:06
Hasleo Backup Suite V5.6.2.1
Hasleo Backup Suit...harlan4096 — 17:41
Opera 128.0.5807.52
Hello! New upda...harlan4096 — 17:39
Brave 1.87.192
Release v1.87.192 ...harlan4096 — 17:38

[-]
Birthdays
Today's Birthdays
avatar (45)tukraNax
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>