Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #agenttesla #RAT #passwdstealer #FTP
- https://pastebin.com/SKNts0Es
- previous_contact:
- 29/10/19 https://pastebin.com/RinpBPvy
- 03/09/19 https://pastebin.com/zhJvDz8M
- 09/01/19 https://pastebin.com/MdDfZDdb
- 16/10/18 https://pastebin.com/d5DxTRrB
- 04/10/18 https://pastebin.com/JYShuXn4
- 11/10/18 https://pastebin.com/bkCSvJvM
- FAQ:
- https://radetskiy.wordpress.com/2018/10/19/ioc_agenttesla_111018/
- attack_vector
- --------------
- email attach .png > URL link > 7zip > exe
- email_headers
- --------------
- Received: from rin43152.imocstudio.com (rin43152.imocstudio.com [82.223.43.152])
- Received: from webmail.coelba.cat (localhost.localdomain [127.0.0.1])
- Date: Fri, 12 Jun 2020 05:28:30 +0100
- From: Олена Кушніренко <proveedores@coelba.cat>
- To: undisclosed-recipients:;
- Subject: Червневий платіж
- User-Agent: Roundcube Webmail/1.4.3
- X-Sender: proveedores@coelba.cat
- files
- --------------
- SHA-256 b87ebc342282049b1c016f8a8eb93c4ccd95c9de86c169baf6b914fddbcacde1
- File name 1122291890.7z [ 7-zip archive data, version 0.4 ]
- File size 237.94 KB (243646 bytes)
- SHA-256 0ccd69ab1e1a3514a7934ccf5647a18d1cc171843e719055b3ece0a1e7708fcc
- File name 1122291890.exe [.NET executable]
- File size 613.00 KB (627712 bytes)
- SHA-256 4c7ce63cd966e72e5d94f6dc8b0f82cec35b88b1a8d24305c52a7106cdad5ad9
- File name InstallUtil.exe [ .NET executable ]
- File size 39.67 KB (40624 bytes)
- activity
- **************
- PL_SCR
- https://www.mediafire.com/file/bl8v4v4x028vf9z/1122291890.7z/file
- C2
- 77.88.21.158:587 smtp.yandex{.} com
- netwrk
- --------------
- 77.88.21.158 smtp.yandex.com
- comp
- --------------
- InstallUtil.exe 3336 TCP 77.88.21.158 587 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\atesla.exe
- C:\tmp\InstallUtil.exe
- persist
- --------------
- n/a
- drop
- --------------
- C:\tmp\InstallUtil.exe
- # # #
- https://www.virustotal.com/gui/file/b87ebc342282049b1c016f8a8eb93c4ccd95c9de86c169baf6b914fddbcacde1/details
- https://www.virustotal.com/gui/file/0ccd69ab1e1a3514a7934ccf5647a18d1cc171843e719055b3ece0a1e7708fcc/details
- https://www.virustotal.com/gui/file/4c7ce63cd966e72e5d94f6dc8b0f82cec35b88b1a8d24305c52a7106cdad5ad9/details
- https://analyze.intezer.com/#/analyses/fe86343e-1507-4d31-bc30-7ed1ea6844f7
- VR
Add Comment
Please, Sign In to add comment