Back to All Attacks
Attack Details
Attack Date:
Jun 16, 2022

Fake Document Link-based Malware Attack

Initial Email Content

Subject
Re: School Advisory Council
Body

Greetings!


Please check the documents as one document available via the link lower:



hXXps://drive[.]google[.]com/uc?export=download&id=1aljY2OitxCFTLJURYOKgUjB9FSvHxCK6&confirm=t


File password: E98346


Good morning! 


My name is [Teacher Name] and I am one of the teacher liaisons for [School Name]'s School Advisory Council. 


This is a group of stakeholders (community members, school staff, students, and families) who come together to discuss how to support our school community. 


Attached is a flyer for our upcoming December meetings. The first, December 9th, will be held at 5pm virtually at this link: .


We hope yopu are able to join! Pleae do not hesitate to reach out to me if you have any questions! 


Best,

[Teacher Name]

Attack Screenshots

No items found.

Malicious Artifacts

Additional Indicators of Compromise

Type

Description

No items found.

Attack Description

This link-based attack impersonates an external third party using an external compromised account and a fake document theme to deliver malware.

Analysis Overview

Tactic
External Compromised Account
Goal
Malware Delivery
Impersonated Party
External Party - Other
Vector
Link-based
Theme
Fake Document
Language