Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: DRIDEX
- SUBJECTS OBSERVED
- Past Due Invoice No. #519137
- SENDERS OBSERVED
- Aila Melony <replyto@ereplysstrangelife[.]us>
- EMAIL BODY
- Good morning,
- Please see attached revised Invoice #928971, removing the Fourteen Day Notice Charge from both units. Sorry for the inconvenience.
- Should you have any questions, please do not hesitate to contact us.
- Aila Melony
- Grand Pointe Park Apartments
- 161 Clubhouse Drive
- Poughkeepsie, NY 12603
- Phone: (845) 486-8000
- Website: www[.]grandpointeparkapts[.]com
- DOCUMENT FILE HASHES
- 892337[.]xlsm
- 836ee6f0431514cc7f31358c138020ad
- PAYLOAD FILE HASHES
- flpaoql[.]exe
- 54e6654dec830080b8181b22b2f5593f
- DRIDEX PAYLOAD DISTRIBUTION URLS
- hxxp://terracotia[.]xyz/flpaoql[.]exe
- DRIDEX C2s
- hxxps://51[.]15[.]7[.]145
- hxxps://192[.]99[.]41[.]136:981
- hxxps://198[.]27[.]69[.]201:4643
- hxxps://198[.]20[.]228[.]10:3389
- SUPPORTING EVIDENCE
- https://urlhaus.abuse.ch/url/406803/
- https://www.virustotal.com/gui/file/16236a7967ffcae726ad1c8fff934e7c852ea2216d28bd73f26beb4d74a30bc0/detection
Add Comment
Please, Sign In to add comment