Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: URSNIF (Gozi / ISFB)
- SUBJECTS OBSERVED
- Subjects were from stolen existing email threads.
- SENDERS OBSERVED
- MALDOC DOWNLOAD URLS
- https://1drv.ms/u/s!AtBlemOC0Q1pd4CN8VJWYHnJBw0?e=ismUCc
- https://1drv.ms/u/s!AvM5mBtIMcgibvCR9VNK3nsXaO0?e=3wLGd5
- https://onedrive.live.com/?authkey=%21APCR9VNK3nsXaO0&cid=22C831481B9839F3&id=22C831481B9839F3%21110&parId=22C831481B9839F3%21104&action=locate
- https://onedrive.live.com/?authkey=%21AICN8VJWYHnJBw0&cid=690DD182637A65D0&id=690DD182637A65D0%21119&parId=690DD182637A65D0%21104&action=locate
- ZIP FILE HASHES
- documentation_67198.zip
- 3cf67ced1a6f6949bd1e7b1f7a2b3a92
- information_48447.zip
- a717b5ea2aa061688f1842c8afcb44c3
- VBS FILE HASHES
- documentation_67198.vbs
- 7e4d4e318c85af75ce9bb40e83a3c051
- information_48447.vbs
- 490181c69f494126eb586e622b93d5ed
- URSNIF C2
- gtr.antoinfer.com
- app.bighomegl.at
- SUPPORTING EVIDENCE
- https://twitter.com/ps66uk/status/1420875603851497477
- https://app.any.run/tasks/18a76498-793c-4c5d-a28c-835aab8739bb/
- https://tria.ge/210729-wvpcwx5t4s
Advertisement
Add Comment
Please, Sign In to add comment