ExecuteMalware

2020-08-07 TA505 IOCs

Aug 7th, 2020
10,381
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.72 KB | None | 0 0
  1. THREAT ATTRIBUTION: TA505
  2.  
  3. SUBJECTS OBSERVED
  4. Pension certificates
  5.  
  6. SENDERS OBSERVED
  7. Roger[.]Dickenson@3sref[.]com
  8. Roger[.]Dickenson@apsara[.]co[.]id
  9. Roger[.]Dickenson@buehler-velos[.]ch
  10. Roger[.]Dickenson@clearcutcomputing[.]com
  11. Roger[.]Dickenson@compedgesolutions[.]co[.]ke
  12. Roger[.]Dickenson@dec[.]fca[.]unam[.]mx
  13. Roger[.]Dickenson@deliveryproprio[.]com[.]br
  14. Roger[.]Dickenson@emsholdings[.]co[.]za
  15. Roger[.]Dickenson@extin[.]co[.]mz
  16. Roger[.]Dickenson@grauvogl[.]org
  17. Roger[.]Dickenson@jumbo-computer[.]com
  18. Roger[.]Dickenson@kntv[.]sumy[.]ua
  19. Roger[.]Dickenson@lakris[.]no
  20. Roger[.]Dickenson@manquehue[.]net
  21. Roger[.]Dickenson@narus-pass[.]com
  22. Roger[.]Dickenson@portersliquor[.]com[.]au
  23. Roger[.]Dickenson@radnoti-pecs[.]hu
  24. Roger[.]Dickenson@residenciapatricia[.]com
  25. Roger[.]Dickenson@santecite[.]fr
  26. Roger[.]Dickenson@sedelecstore[.]com
  27. Roger[.]Dickenson@spshimbun[.]com[.]br
  28. Roger[.]Dickenson@suncast[.]jp
  29. Roger[.]Dickenson@terek[.]hu
  30. Roger[.]Dickenson@weiskirchner[.]at
  31.  
  32. MALDOC DISTRIBUTION URLS
  33. Opening the .html file points here - these are landing pages which then forward to dl[.]river-store (below) for a reCaptcha
  34. hxxp://archifaktura[.]hu/nfxdutl[.]html
  35. hxxp://www[.]davion[.]plus[.]com/iscyqz[.]html
  36.  
  37. The reCaptcha and the .xls file downloads are located here:
  38. hxxps://dl[.]river-store[.]com/
  39.  
  40. HTML FILE HASHES
  41. b603b63140b5616d13f289174fceb5a9
  42. 15ae6410dec574e473135186d552ecfc
  43.  
  44. EXCEL FILE HASHES
  45. 28e8cbdfc88662203258c9c4145974bf
  46. 413288a05bb379241afd2d03b0dc5fe9
  47. 99c0efc023fae2d1db32c4d5691c68e7
  48. a7764976e7f996c514bc8bea58986070
  49. f3cf456f0717f432be76ec3408bc5050
  50.  
  51. TA505 C2
  52. Traffic to:
  53. 23[.]163[.]0[.]37:443
  54.  
  55. which resolves to:
  56. none-class[.]com
  57.  
  58. SUPPORTING EVIDENCE
  59. hxxps://urlhaus[.]abuse[.]ch/url/427135/
Add Comment
Please, Sign In to add comment