TF-MAL-elf.finaldraft
📛 Threat Title
Malware family: FINALDRAFT
Description
ThreatFox malware family `elf.finaldraft`. Printable name: FINALDRAFT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.finaldraft
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.finaldraft
IOC database
- Type
- domain
- Value
elf.finaldraft- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.finaldraft
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.finaldraft
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Researchers identified a previously unknown malware family that utilizes Outlook as a communication channel via the Microsoft Graph API. This post-exploitation framework includes a loader, a backdoor, and several modules designed for advanced intrusion activities.
-
web:cirt.gy
A newly discovered malware , FinalDraft , has been leveraging Outlook email drafts for stealthy command-and-control (C2) communication. The malware was uncovered by Elastic Security Labs during an investigation into cyber-espionage attacks against a South American foreign ministry.
-
web:cyberpress.org
This operation leverages a novel malware family , FINALDRAFT , targeting both Windows and Linux systems. The campaign has been linked to attacks on a South American foreign ministry and entities in Southeast Asia, showcasing the group's technical capabilities and operational missteps.
-
web:cybersecurefox.com
Security researchers at Elastic Security Labs have uncovered a sophisticated new malware family dubbed FinalDraft , which employs an innovative technique to conceal its command-and-control (C2) communications through Microsoft Outlook draft folders.
-
web:cybersecuritynews.com
A new family of malware has been discovered that leverages Microsoft Outlook as a communication channel via the Microsoft Graph API. This sophisticated malware includes a custom loader and backdoor, known as PATHLOADER and FINALDRAFT , respectively.
-
web:dailysecurityreview.com
FinalDraft malware uses Outlook email drafts for covert command-and-control communication, enabling data exfiltration, process injection, and lateral movement with minimal traces. The malware , part of the REF7707 cyber espionage campaign, targets high-value institutions.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the FINALDRAFT malware family including references, samples and yara signatures.
-
web:thehackernews.com
REF7707 deployed FINALDRAFT malware , using Microsoft Graph API for stealthy command-and-control in a global espionage campaign.
-
web:www.bleepingcomputer.com
A new malware called FinalDraft has been using Outlook email drafts for command-and-control communication in attacks against a ministry in a South American country.
-
web:www.elastic.co
You've Got Malware : FINALDRAFT Hides in Your Drafts During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using Microsoft's Graph API for C2 communications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.