ExecuteMalware

2020-11-24 Remcos IOCs

Nov 24th, 2020
5,828
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.84 KB | None | 0 0
  1. THREAT ATTRIBUTION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Citbank Payment Advice Notice For Vendor-- <Company Name>
  5. Wells Fargo Payment Advice Notification -<Company Name> WF11232020
  6.  
  7. SENDERS OBSERVED
  8.  
  9. MALDOC FILE HASHES
  10. Payment-Advice.xls
  11. d0eec012f6b2d39a4d3b0091588d4d23
  12.  
  13. Remit_Advice.xls
  14. 75ecb80a0cfeb25ac23b4fe0c611ca7a
  15.  
  16. ach.vbs
  17. 7eb75ac29bcdb9b04ffd7be21be218c0
  18.  
  19. PAYLOAD FILE HASHES
  20. fila.jpg
  21. 5aef2c7a517e06b2ff42c55b2546a44e
  22.  
  23. MALDOC DOWNLOAD URLS
  24. http://creditcollectionglobal.co/holder/word.vbs
  25. http://creditcollectionglobal.co/holder/ach.vbs
  26.  
  27. PAYLOAD URL
  28. http://creditcollectionglobal.co/mint/fila.jpg
  29.  
  30. REMCOS C2
  31. daemontime.myq-see.com
  32. 79.134.225.120:12489
  33.  
  34. SUPPORTING EVIDENCE
  35. https://app.any.run/tasks/c6b92e79-f5dd-40b9-a294-01b14f06d9b3/
Advertisement
Add Comment
Please, Sign In to add comment