s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.finaldraft

📛 Threat Title

Malware family: FINALDRAFT

Category: FINALDRAFT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.finaldraft`. Printable name: FINALDRAFT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.finaldraft VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.finaldraft

IOC database

Type
domain
Value
elf.finaldraft
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.finaldraft

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.finaldraft

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Researchers identified a previously unknown malware family that utilizes Outlook as a communication channel via the Microsoft Graph API. This post-exploitation framework includes a loader, a backdoor, and several modules designed for advanced intrusion activities.

  • web:cirt.gy

    A newly discovered malware , FinalDraft , has been leveraging Outlook email drafts for stealthy command-and-control (C2) communication. The malware was uncovered by Elastic Security Labs during an investigation into cyber-espionage attacks against a South American foreign ministry.

  • web:cyberpress.org

    This operation leverages a novel malware family , FINALDRAFT , targeting both Windows and Linux systems. The campaign has been linked to attacks on a South American foreign ministry and entities in Southeast Asia, showcasing the group's technical capabilities and operational missteps.

  • web:cybersecurefox.com

    Security researchers at Elastic Security Labs have uncovered a sophisticated new malware family dubbed FinalDraft , which employs an innovative technique to conceal its command-and-control (C2) communications through Microsoft Outlook draft folders.

  • web:cybersecuritynews.com

    A new family of malware has been discovered that leverages Microsoft Outlook as a communication channel via the Microsoft Graph API. This sophisticated malware includes a custom loader and backdoor, known as PATHLOADER and FINALDRAFT , respectively.

  • web:dailysecurityreview.com

    FinalDraft malware uses Outlook email drafts for covert command-and-control communication, enabling data exfiltration, process injection, and lateral movement with minimal traces. The malware , part of the REF7707 cyber espionage campaign, targets high-value institutions.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the FINALDRAFT malware family including references, samples and yara signatures.

  • web:thehackernews.com

    REF7707 deployed FINALDRAFT malware , using Microsoft Graph API for stealthy command-and-control in a global espionage campaign.

  • web:www.bleepingcomputer.com

    A new malware called FinalDraft has been using Outlook email drafts for command-and-control communication in attacks against a ministry in a South American country.

  • web:www.elastic.co

    You've Got Malware : FINALDRAFT Hides in Your Drafts During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using Microsoft's Graph API for C2 communications.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.