Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #GuLoader #AnonVNC #MeshAgent
- https://pastebin.com/9SYknZHD
- previous_contact:
- 12/08/24
- FAQ:
- https://github.com/Ylianst/MeshAgent
- https://cert.gov.ua/article/6280345
- attack_vector
- --------------
- email URL > privat24x _com > reCaptcha > .exe > get config > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Fri, 16 Aug 2024 11:19:40 +0300
- From: Лазарев Абрам Робертович <finmons @privatbank _ua>
- Subject: Запит інформації № 1500750 вiд: 16.08.2024
- Reply-To: "public @cip _gov _ua" <public @cip _gov _ua>
- Received: from smtp _dwku _com ([223 _130 _104 _222])
- Received: from 193 _33 _153 _89 (HELO 193 _33 _153 _89) (FROM: yeotaeshik @dwku _com)
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 fd21bb2bd77692d295d1bb956325bfa23fd439a6982f2f5bbd8a92733e69dc1a
- File name Scan_Docs#630739.exe
- File size 587.56 KB (601664 bytes)
- SHA-256 0b9189304936322f58e164c985e58e12e3ed32787bc2efe67df5d9a7698fe2b9
- File name Scan_Docs#672910
- File size 587.56 KB (601664 bytes)
- SHA-256 ef8f4aa052f414afc1843473cb33633c509b9ccacdb4da055d51daa100b583cf
- File name nPZGZs136.bin
- File size 2.09 MB (2195008 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR privat24x _com
- privat24x _com /linkss.txt
- C2 186 _2 _171 _76
- netwrk
- --------------
- 190 _115 _18 _43 gbshost _net 443 TLSv1.3 Client Hello
- 186 _2 _171 _76 443 TLSv1.2 Client Hello
- comp
- --------------
- Scan_Docs#672910.exe 190 _115 _18 _43 443
- Scan_Docs#672910.exe 186 _2 _171 _76 443
- proc
- --------------
- C:\Users\User01\Downloads\files1608\Scan_Docs#672910.exe
- C:\Users\User01\Downloads\files1608\Scan_Docs#672910.exe
- persist
- --------------
- Siam Computer (MD Kamrul Hassan) C:\Users\User01\AppData\Roaming\Tjenesteivriges\Fondler.exe Sat Aug 17 15:04:49 2024
- drop
- --------------
- C:\Users\User01\Downloads\files1608\Scan_Docs#672910.exe
- # # # # # # # #
- additional info
- # # # # # # # #
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/fd21bb2bd77692d295d1bb956325bfa23fd439a6982f2f5bbd8a92733e69dc1a/details
- https://www.virustotal.com/gui/file/0b9189304936322f58e164c985e58e12e3ed32787bc2efe67df5d9a7698fe2b9/details
- https://www.virustotal.com/gui/file/ef8f4aa052f414afc1843473cb33633c509b9ccacdb4da055d51daa100b583cf/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement