ExecuteMalware

2021-04-14 Agent Tesla IOCs

Apr 14th, 2021
17,172
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.73 KB | None | 0 0
  1. THREAT IDENTIFICATION: AGENT TESLA
  2.  
  3. SUBJECTS OBSERVED
  4. FW: RE: confirm bank account
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. CONFIRM YOUR ACCOUNT_PDF.UU
  10. f81c3488a4d9e51fbf68ea591b35719a
  11.  
  12. AGENT TESLA PAYLOAD FILE HASHES
  13. CONFIRM YOUR ACCOUNT_PDF.exe
  14. 74173b957e2e703074eef531996348c4
  15.  
  16. AGENT TESLA ESMTP DESTINATION
  17. mail.jumatsedekah.com
  18. https://101.50.1.12:587
  19.  
  20. ADDITIONAL URL
  21. http://bornforthis.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-6B711D1EC6B765989791BAB1375373A5.html
  22.  
  23. SUPPORTING EVIDENCE
  24. https://www.virustotal.com/gui/file/8b2e93f410996ef2b5eac9cc2d686657cb401081ba41f9df156930e16da7723a/detection
  25. https://app.any.run/tasks/e8ee160d-9097-4202-a2e2-173eb5d2305e/
Advertisement
Add Comment
Please, Sign In to add comment