← Back to Pulse Feed
PULSE DETAIL
A malicious host mimicking ICICI Bank has been discovered, along with a fraudulent app disguised as ICICI Helpdesk. The phishing domain, cppcccare.com, is hosted on an ASN known for various malicious activities. The fraudulent app, named 'ICICI.apk', is detected as a Trojan Banker, Keylogger, and SMSspy. It's believed to have been operational since August 2024, with a falsely inflated download count of 500K+. The app's description matches other fraudulent apps, indicating a broader phishing campaign. The incident has been reported to the bank, hosting provider, and CERT-IN authorities. The article provides detailed technical information about the malicious domain and app, including file hashes and package details.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | df1e45aa0435509d552602ca1b84ccb6 | — | 2024-09-24 | |
| FileHash-SHA1 | bde9068c2deb1e3dcf9b7646dc8960dbea97d8b3 | — | 2024-09-24 | |
| FileHash-SHA256 | cd89b4cc7dc155f30db39e31b30894ed11f3fb6ad0fe5b2d014b123e333084c6 | — | 2024-09-24 | |
| domain | cppcccare.com | — | 2024-09-24 |