ExecuteMalware

2021-08-04 Agent Tesla IOCs

Aug 4th, 2021
15,361
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.88 KB | None | 0 0
  1. THREAT ATTRIBUTION: AGENT TESLA
  2.  
  3. SUBJECTS OBSERVED
  4. INQUIRY RFQ No3756368 Norma Pacific Pty Ltd
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. inquiry RFQ No3756368.xlsx
  10. 288366c7e10c7efde9c800337ad0791c
  11.  
  12. AGENT TESLA PAYLOAD DOWNLOAD URLS
  13. http://192.3.13.125/god/ongod.exe
  14.  
  15. AGENT TESLA PAYLOAD FILE HASHES
  16. ongod.exe
  17. 2254a05b64b7f1b84739aa01888e1d0d
  18.  
  19. Renamed to:
  20. vbc.exe
  21. 2254a05b64b7f1b84739aa01888e1d0d
  22.  
  23. AGENT TESLA ESMTP DESTINATION
  24. https://208.91.198.143:587
  25. us2.outbound.mailhostbox.com
  26.  
  27. EXFILTRATION INFORMATION
  28. Password: PAPARAZI3116
  29.  
  30. SUPPORTING EVIDENCE
  31. https://urlhaus.abuse.ch/url/1505248/
  32. https://www.virustotal.com/gui/file/d31a1d9e7d79728f0fd4a581a9f98fd54b9f468aa3fc17fc436e52a13dc92124/detection
  33. https://www.virustotal.com/gui/file/66eee5b2f2d5356fc7e5aaf37b28536b36c8c13158e80972b6404bf3218e9574/detection
  34.  
  35.  
Advertisement
Add Comment
Please, Sign In to add comment