Block FAKEUPDATES
aka FakeUpdate
, SocGholish
malware
#745
Labels
Code Update 🔔
Code Update
enhancement 👍
New feature or request
In-progress
In-progress
Priority: Medium
Priority: Medium
Enhancement idea
FAKEUPDATES
akaFakeUpdate
,SocGholish
malware.Description
FAKEUPDATES
is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. It writes the payloads to disk prior to launching them.FAKEUPDATES
has led to further compromise via additional malware families that includeCHTHONIC
,DRIDEX
,EMPIRE
,KOADIC
,DOPPELPAYMER
andAZORULT
.FAKEUPDATES
has been heavily used byUNC1543
, a financially motivated group.Screenshots
n/a
Links
https://threatfox.abuse.ch/browse/malware/js.fakeupdates/
https://malpedia.caad.fkie.fraunhofer.de/details/js.fakeupdates
https://www.malwarebytes.com/blog/news/2024/12/malicious-ad-distributes-socgholish-malware-to-kaiser-permanente-employees
IOC
I2P websites
n/a
IPFS websites
n/a
Tor2web websites
n/a
TOR websites
n/a
URL's
n/a
Folders
n/a
Sub-Domains
n/a
Domains
n/a
Package Names
n/a
IP's
n/a
ASN's
n/a
Emails
n/a
Wallet addresses
n/a
Mining pool addresses
n/a
The text was updated successfully, but these errors were encountered: