MAPIget
Description
This malware utility is a set of two files that operate in conjunction to extract email messages and attachments from an Exchange server. In order to operate successfully, these programs require authentication credentials for a user on the Exchange server, and must be run from a machine joined to the domain that has Microsoft Outlook installed (or equivalent software that provides the Microsoft ‘Messaging API’ (MAPI) service).
Names
Name |
---|
MAPIget |
Category
Malware
Type
- Info stealer
Information
- https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf
- http://contagiodump.blogspot.com/2013/03/mandiant-apt1-samples-categorized-by.html
Malpedia
Other Information
Uuid
e4cd147b-e6a7-416f-99df-56fa7a63271f
Last Card Change
2020-04-23