home.social

#malvertizing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malvertizing, aggregated by home.social.

  1. 2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at malware-traffic-analysis.net/2

  2. 2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at malware-traffic-analysis.net/2

  3. 2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at malware-traffic-analysis.net/2

  4. 2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at malware-traffic-analysis.net/2

  5. 2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at malware-traffic-analysis.net/2

  6. 2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site

    I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at linkedin.com/posts/unit42_2025 and x.com/Unit42_Intel/status/1882

    Details on that infection are at: github.com/PaloAltoNetworks/Un

    The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.

    The exercise #pcap is at malware-traffic-analysis.net/2

  7. 2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site

    I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at linkedin.com/posts/unit42_2025 and x.com/Unit42_Intel/status/1882

    Details on that infection are at: github.com/PaloAltoNetworks/Un

    The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.

    The exercise #pcap is at malware-traffic-analysis.net/2

  8. 2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site

    I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at linkedin.com/posts/unit42_2025 and x.com/Unit42_Intel/status/1882

    Details on that infection are at: github.com/PaloAltoNetworks/Un

    The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.

    The exercise #pcap is at malware-traffic-analysis.net/2

  9. 2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site

    I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at linkedin.com/posts/unit42_2025 and x.com/Unit42_Intel/status/1882

    Details on that infection are at: github.com/PaloAltoNetworks/Un

    The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.

    The exercise #pcap is at malware-traffic-analysis.net/2

  10. 2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site

    I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at linkedin.com/posts/unit42_2025 and x.com/Unit42_Intel/status/1882

    Details on that infection are at: github.com/PaloAltoNetworks/Un

    The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.

    The exercise #pcap is at malware-traffic-analysis.net/2

  11. Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages

    🧊​ Infection Chain:

    ➡️​ Google search for "adobe reader"
    ↪️​ Google ad click
    ↪️​ TDS redirect: `likhs299us[.]tech`
    🎣​ Fake website: vvw-adobe[.]top
    ↪️​ Download of malware from firebase (.zip containing a .iso)
    🗄️​ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso

    #IcedID C2: plivetrakoy[.]com

    #IOCs:
    🔗​ virustotal.com/gui/file/be9ac5
    🔗​ virustotal.com/gui/ip-address/
    #ThreatIntel #Malware #CTI

  12. Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages

    🧊​ Infection Chain:

    ➡️​ Google search for "adobe reader"
    ↪️​ Google ad click
    ↪️​ TDS redirect: `likhs299us[.]tech`
    🎣​ Fake website: vvw-adobe[.]top
    ↪️​ Download of malware from firebase (.zip containing a .iso)
    🗄️​ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso

    #IcedID C2: plivetrakoy[.]com

    #IOCs:
    🔗​ virustotal.com/gui/file/be9ac5
    🔗​ virustotal.com/gui/ip-address/
    #ThreatIntel #Malware #CTI

  13. Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages

    🧊​ Infection Chain:

    ➡️​ Google search for "adobe reader"
    ↪️​ Google ad click
    ↪️​ TDS redirect: `likhs299us[.]tech`
    🎣​ Fake website: vvw-adobe[.]top
    ↪️​ Download of malware from firebase (.zip containing a .iso)
    🗄️​ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso

    #IcedID C2: plivetrakoy[.]com

    #IOCs:
    🔗​ virustotal.com/gui/file/be9ac5
    🔗​ virustotal.com/gui/ip-address/
    #ThreatIntel #Malware #CTI

  14. Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages

    🧊​ Infection Chain:

    ➡️​ Google search for "adobe reader"
    ↪️​ Google ad click
    ↪️​ TDS redirect: `likhs299us[.]tech`
    🎣​ Fake website: vvw-adobe[.]top
    ↪️​ Download of malware from firebase (.zip containing a .iso)
    🗄️​ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso

    #IcedID C2: plivetrakoy[.]com

    #IOCs:
    🔗​ virustotal.com/gui/file/be9ac5
    🔗​ virustotal.com/gui/ip-address/
    #ThreatIntel #Malware #CTI

  15. Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages

    🧊​ Infection Chain:

    ➡️​ Google search for "adobe reader"
    ↪️​ Google ad click
    ↪️​ TDS redirect: `likhs299us[.]tech`
    🎣​ Fake website: vvw-adobe[.]top
    ↪️​ Download of malware from firebase (.zip containing a .iso)
    🗄️​ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso

    #IcedID C2: plivetrakoy[.]com

    #IOCs:
    🔗​ virustotal.com/gui/file/be9ac5
    🔗​ virustotal.com/gui/ip-address/
    #ThreatIntel #Malware #CTI

  16. Sophos has observed new #IcedID activity stemming from malvertizing.

    Infection Chain:
    ➡️ Google search for “slack”
    ↪️ Malicious ad click #malvertizing
    ↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
    ↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
    ➡️ Download: setup_win_13-12-2022_17-15-46.zip, which contained the file setup_win_13-12-2022_17-15-46.msi

    Rundll32 was then invoked, referencing a DLL staged under %APPDATA%\Local\Temp\tmp*.dll

    Connections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)

    Seemingly related lure sites can be found via URLScan - urlscan.io/search/#www-*.top

  17. Sophos has observed new #IcedID activity stemming from malvertizing.

    Infection Chain:
    ➡️ Google search for “slack”
    ↪️ Malicious ad click #malvertizing
    ↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
    ↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
    ➡️ Download: setup_win_13-12-2022_17-15-46.zip, which contained the file setup_win_13-12-2022_17-15-46.msi

    Rundll32 was then invoked, referencing a DLL staged under %APPDATA%\Local\Temp\tmp*.dll

    Connections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)

    Seemingly related lure sites can be found via URLScan - urlscan.io/search/#www-*.top

  18. Sophos has observed new #IcedID activity stemming from malvertizing.

    Infection Chain:
    ➡️ Google search for “slack”
    ↪️ Malicious ad click #malvertizing
    ↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
    ↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
    ➡️ Download: setup_win_13-12-2022_17-15-46.zip, which contained the file setup_win_13-12-2022_17-15-46.msi

    Rundll32 was then invoked, referencing a DLL staged under %APPDATA%\Local\Temp\tmp*.dll

    Connections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)

    Seemingly related lure sites can be found via URLScan - urlscan.io/search/#www-*.top

  19. Sophos has observed new #IcedID activity stemming from malvertizing.

    Infection Chain:
    ➡️ Google search for “slack”
    ↪️ Malicious ad click #malvertizing
    ↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
    ↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
    ➡️ Download: setup_win_13-12-2022_17-15-46.zip, which contained the file setup_win_13-12-2022_17-15-46.msi

    Rundll32 was then invoked, referencing a DLL staged under %APPDATA%\Local\Temp\tmp*.dll

    Connections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)

    Seemingly related lure sites can be found via URLScan - urlscan.io/search/#www-*.top

  20. Sophos has observed new #IcedID activity stemming from malvertizing.

    Infection Chain:
    ➡️ Google search for “slack”
    ↪️ Malicious ad click #malvertizing
    ↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
    ↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
    ➡️ Download: setup_win_13-12-2022_17-15-46.zip, which contained the file setup_win_13-12-2022_17-15-46.msi

    Rundll32 was then invoked, referencing a DLL staged under %APPDATA%\Local\Temp\tmp*.dll

    Connections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)

    Seemingly related lure sites can be found via URLScan - urlscan.io/search/#www-*.top