Fake Microsoft Teams website used to download IcedID malware

πŸŒβ€‹ mlcrosofteams[.]top
⬇️​ Downloads .zip containing .msi

#IcedID C2: whothitheka[.]com

This is likely being distributed by #malvertising but I wasn't able to capture the advertisement

193.222.62[.]37 is also hosting fake IRS & Royal mail websites
πŸ¦β€‹ irs-forms[.]top
πŸ¦β€‹ royalmail.orders-info[.]uk

πŸ”—https://www.virustotal.com/gui/file/8ed2026fd98d54f9ad85d721223b60bd8b6c1362faeb4c24492d2bb63a7c357b/details
πŸ”—https://urlscan.io/result/a0e5de3e-75ea-46f4-8340-0ab09c440850/
πŸ”—https://urlscan.io/ip/193.222.62.37

#CTI #threatintelligence #ThreatIntel #Malware

VirusTotal

VirusTotal

@th3_protoCOL More #IcedID domains:

item-tracking[.]link
mlcrosofteams[.]top
my-deliveries[.]link
orders-info[.]uk
parcel-info[.]link
royaimaii[.]link
royaimail[.]uk
royalmaii.co[.]uk
royalmaii[.]uk
vvv-discord[.]top
vwv-discord[.]top
vwvv-discord[.]top
webeex[.]top
wvvw-citrix[.]top
wvw-adobe[.]top
wvw-irs-forms[.]top
wwv-slack[.]top
www-adobecom[.]top
www-anydeskcom[.]top
www-basecamp[.]top
www-fortlnet[.]top
www-llbreofflce[.]top
www-microsofteams[.]top
www-obsproject[.]top
www-onenote[.]top
www-realvnc[.]top
www-thunderblrd[.]top
wwww-citrix[.]top
wwww-irs-form[.]top
wwww-teamvlewer[.]top