ExecuteMalware

2021-07-24 Remcos IOCs

Jul 23rd, 2021
15,506
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. THREAT IDENTIFICATION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Bank of America Payment/Remittance Advice
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. BoFA Remittance Advice-21721.doc
  10. d9351f959e1b09a54714ce11437581bb
  11.  
  12. INTERMEDIATE PAYLOAD URLS
  13. http://192.227.158.111/jug.js
  14. http://192.227.158.111/fud.jpg
  15.  
  16. INTERMEDIATE PAYLOAD FILE HASHES
  17. jug.js
  18. 78f0668dbe848311be3b827e9e355d37
  19.  
  20. fud.jpg
  21. e3315478336c1e8acd0fdfd8b056fa36
  22.  
  23. REMCOS C2
  24. twistednerd.dvrlists.com
  25. https://213.152.187.215:41078
  26.  
  27. SUPPORTING EVIDENCE
  28. https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
  29. https://urlhaus.abuse.ch/browse.php?search=http%3A%2F%2F192.227.158.111
Advertisement
Add Comment
Please, Sign In to add comment