Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: REMCOS RAT
- SUBJECTS OBSERVED
- Citbank Payment Advice Notice For Vendor-- <Company Name>
- Wells Fargo Payment Advice Notification -<Company Name> WF11232020
- SENDERS OBSERVED
- MALDOC FILE HASHES
- Payment-Advice.xls
- d0eec012f6b2d39a4d3b0091588d4d23
- Remit_Advice.xls
- 75ecb80a0cfeb25ac23b4fe0c611ca7a
- ach.vbs
- 7eb75ac29bcdb9b04ffd7be21be218c0
- PAYLOAD FILE HASHES
- fila.jpg
- 5aef2c7a517e06b2ff42c55b2546a44e
- MALDOC DOWNLOAD URLS
- http://creditcollectionglobal.co/holder/word.vbs
- http://creditcollectionglobal.co/holder/ach.vbs
- PAYLOAD URL
- http://creditcollectionglobal.co/mint/fila.jpg
- REMCOS C2
- daemontime.myq-see.com
- 79.134.225.120:12489
- SUPPORTING EVIDENCE
- https://app.any.run/tasks/c6b92e79-f5dd-40b9-a294-01b14f06d9b3/
Advertisement
Add Comment
Please, Sign In to add comment