PULSE NAME
Grandoreiro Banking Malware Resurfaces for Tax Season
WHITE AlienVault 2022-05-27 Modified: 2022-06-26
17
IOCs
MEDIUM VOLUME
Researchers observed in early April a Grandoreiro malware campaign targeting bank users from Brazil, Spain, and Mexico. The campaign exploits the tax season in target countries by sending out tax-themed phishing emails.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Grandoreiro
Indicators of Compromise (3 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://167.114.43.27:4433/mrrrpx2503.zip 2022-05-27
URL http://belfaro.com.br/admin/PROCESSO-02028.82655.2019.550.pdf 2022-05-27
URL http://belfaro.com.br/admin/nota.php?file=docprocesso27032022.zip 2022-05-27