ExecuteMalware

2021-07-29 Ursnif IOCs

Jul 29th, 2021
15,246
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.10 KB | None | 0 0
  1. THREAT IDENTIFICATION: URSNIF (Gozi / ISFB)
  2.  
  3. SUBJECTS OBSERVED
  4. Subjects were from stolen existing email threads.
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC DOWNLOAD URLS
  9. https://1drv.ms/u/s!AtBlemOC0Q1pd4CN8VJWYHnJBw0?e=ismUCc
  10. https://1drv.ms/u/s!AvM5mBtIMcgibvCR9VNK3nsXaO0?e=3wLGd5
  11.  
  12. https://onedrive.live.com/?authkey=%21APCR9VNK3nsXaO0&cid=22C831481B9839F3&id=22C831481B9839F3%21110&parId=22C831481B9839F3%21104&action=locate
  13.  
  14. https://onedrive.live.com/?authkey=%21AICN8VJWYHnJBw0&cid=690DD182637A65D0&id=690DD182637A65D0%21119&parId=690DD182637A65D0%21104&action=locate
  15.  
  16. ZIP FILE HASHES
  17. documentation_67198.zip
  18. 3cf67ced1a6f6949bd1e7b1f7a2b3a92
  19.  
  20. information_48447.zip
  21. a717b5ea2aa061688f1842c8afcb44c3
  22.  
  23. VBS FILE HASHES
  24. documentation_67198.vbs
  25. 7e4d4e318c85af75ce9bb40e83a3c051
  26.  
  27. information_48447.vbs
  28. 490181c69f494126eb586e622b93d5ed
  29.  
  30. URSNIF C2
  31. gtr.antoinfer.com
  32. app.bighomegl.at
  33.  
  34. SUPPORTING EVIDENCE
  35. https://twitter.com/ps66uk/status/1420875603851497477
  36. https://app.any.run/tasks/18a76498-793c-4c5d-a28c-835aab8739bb/
  37. https://tria.ge/210729-wvpcwx5t4s
  38.  
Advertisement
Add Comment
Please, Sign In to add comment