Advertisement
ExecuteMalware

2020-05-28 Misc IOCs

May 28th, 2020
4,200
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.34 KB | None | 0 0
  1.  
  2. ZLoader
  3. -------
  4. SUBJECTS OBSERVED
  5. Receipt data No.70000, from Ansoft
  6.  
  7. SENDERS OBSERVED
  8. broilba.rustytap1988i@aol.com
  9.  
  10. EXCEL FILE HASHES
  11. 76b47a2dc3c5d454bc12c636b705c8a1
  12.  
  13. ZLOADER PAYLOAD URLs
  14. http://newsblog.usflydeals.com/wp-keys.php
  15. https://chaplaincy.covenantuniversity.edu.ng/wp-keys.php
  16.  
  17.  
  18. Remocs 1
  19. --------
  20. MALDOC FILE HASHES
  21. Remittance Advice.xlsm
  22. f87960e83ded6f88bef4a4d6cdeba6f6
  23.  
  24. multistation.vbs
  25. 5d54687f3570148a61b93f8e0e33a986
  26.  
  27. PAYLOAD FILE HASHES
  28. Attack.jpg
  29. 0f3a2512f7220273f08316d38af5e292
  30.  
  31. PAYLOAD URL
  32. http://worldwidetechsecurity.com/Administrator/Multitask/Attack.jpg
  33.  
  34.  
  35. Remcos 2
  36. --------
  37. MALDOC FILE HASHES
  38. ACH Payment.img
  39. 05ce5107a9f59e9b817bd3b45c5a5eeb
  40.  
  41. ACH Payment.vbs
  42. 1ca453fc90bee283ebca6f09ee88e961
  43.  
  44. PAYLOAD FILE HASHES
  45. Attack.jpg.2
  46. e55fcce3c684804829084b586a4a062d
  47.  
  48. PAYLOAD URL
  49. https://cobbtownholiness.com/kings/foldrt/good/luck/Attack.jpg
  50.  
  51.  
  52. Unknown Malware
  53. ---------------
  54. MALDOC FILE HASHES
  55. PO637682 DRAWING ITEMS & PO7387273823_doc.7z
  56. ddc05440d7194bf3b742cc2a0859ce5a
  57.  
  58. PAYLOAD FILE HASHES
  59. PO637682 DRAWING ITEMS & PO7387273823_doc.exe
  60. 4e27900568769c906d602caab43a6045
  61.  
  62. SUPPORTING EVIDENCE
  63. https://www.virustotal.com/gui/file/e83a362528301156b853909e27649e52db6de0bbc81430578fdc3dd0b844586a/detection
  64. https://www.virustotal.com/gui/file/4E27900568769C906D602CAAB43A6045/detection
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement