Advertisement
ExecuteMalware

2021-04-14 Agent Tesla IOCs

Apr 14th, 2021
13,293
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.73 KB | None | 0 0
  1. THREAT IDENTIFICATION: AGENT TESLA
  2.  
  3. SUBJECTS OBSERVED
  4. FW: RE: confirm bank account
  5.  
  6. SENDERS OBSERVED
  7. withanya@teikuro.co.th
  8.  
  9. MALDOC FILE HASHES
  10. CONFIRM YOUR ACCOUNT_PDF.UU
  11. f81c3488a4d9e51fbf68ea591b35719a
  12.  
  13. AGENT TESLA PAYLOAD FILE HASHES
  14. CONFIRM YOUR ACCOUNT_PDF.exe
  15. 74173b957e2e703074eef531996348c4
  16.  
  17. AGENT TESLA ESMTP DESTINATION
  18. mail.jumatsedekah.com
  19. https://101.50.1.12:587
  20.  
  21. ADDITIONAL URL
  22. http://bornforthis.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-6B711D1EC6B765989791BAB1375373A5.html
  23.  
  24. SUPPORTING EVIDENCE
  25. https://www.virustotal.com/gui/file/8b2e93f410996ef2b5eac9cc2d686657cb401081ba41f9df156930e16da7723a/detection
  26. https://app.any.run/tasks/e8ee160d-9097-4202-a2e2-173eb5d2305e/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement