PULSE NAME
FakeBat delivered via several active malvertising campaigns
WHITE AlienVault 2024-03-13 Modified: 2024-03-13
23
IOCs
MEDIUM VOLUME
In February 2024, threat actors distributed the FakeBat malware through malvertising campaigns that abused legitimate websites and cloaking techniques to bypass security checks. The campaigns impersonated popular software to trick users into downloading trojanized installers containing obfuscated PowerShell scripts. FakeBat continues to threaten businesses by compromising ads for software downloads. Defending against the infrastructure and blocking ads can mitigate these types of attacks.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
FakeBat
Indicators of Compromise (23)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 07b0c5e7d77629d050d256fa270d21a152b6ef8409f08ecc47899253aff78029 2024-03-13
FileHash-SHA256 0d906e43ddf453fd55c56ccd6132363ef4d66e809d5d8a38edea7622482c1a7a 2024-03-13
FileHash-SHA256 15ce7b4e6decad4b78fe6727d97692a8f5fd13d808da18cb9d4ce51801498ad8 2024-03-13
FileHash-SHA256 40c9b735d720eeb83c85aae8afe0cc136dd4a4ce770022a221f85164a5ff14e5 2024-03-13
FileHash-SHA256 f7fbf33708b385d27469d925ca1b6c93b2c2ef680bc4096657a1f9a30e4b5d18 2024-03-13
URL http://bezynet.com/Bandicam_7.21_win64.msix 2024-03-13
URL http://bezynet.com/OBS-Studio-30.0.2-Full-Installer-x64.msix 2024-03-13
URL http://church-notes.com/Braavos-Wallet.msix 2024-03-13
URL http://church-notes.com/Epic-Games_Setup.msix 2024-03-13
URL http://church-notes.com/Onenote_setup.msix 2024-03-13
domain ads-analyze.top 2024-03-13
domain ads-pill.top 2024-03-13
domain ads-pill.xyz 2024-03-13
domain ads-tooth.top 2024-03-13
domain bandi-cam.cc 2024-03-13
domain bezynet.com 2024-03-13
domain blcnder.org 2024-03-13
domain church-notes.com 2024-03-13
domain epicgames-store.org 2024-03-13
domain obs-software.cc 2024-03-13
domain onenote-download.com 2024-03-13
domain open-project.org 2024-03-13
domain breavas.app 2024-03-13