Advertisement
ExecuteMalware

2021-07-24 Remcos IOCs

Jul 23rd, 2021
11,573
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. THREAT IDENTIFICATION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Bank of America Payment/Remittance Advice
  5.  
  6. SENDERS OBSERVED
  7. noreply.alerts@edi.bofa.com
  8.  
  9. MALDOC FILE HASHES
  10. BoFA Remittance Advice-21721.doc
  11. d9351f959e1b09a54714ce11437581bb
  12.  
  13. INTERMEDIATE PAYLOAD URLS
  14. http://192.227.158.111/jug.js
  15. http://192.227.158.111/fud.jpg
  16.  
  17. INTERMEDIATE PAYLOAD FILE HASHES
  18. jug.js
  19. 78f0668dbe848311be3b827e9e355d37
  20.  
  21. fud.jpg
  22. e3315478336c1e8acd0fdfd8b056fa36
  23.  
  24. REMCOS C2
  25. twistednerd.dvrlists.com
  26. https://213.152.187.215:41078
  27.  
  28. SUPPORTING EVIDENCE
  29. https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
  30. https://urlhaus.abuse.ch/browse.php?search=http%3A%2F%2F192.227.158.111
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement