ExecuteMalware

2021-08-13 Remcos IOCs

Aug 13th, 2021
15,134
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. THREAT ATTRIBUTION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. PAYMENT REMITTANCE ADVICE
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. ACH Remittance.xls
  10. 3d60d0c1b933856982737fc3b079ff00
  11.  
  12. INTERMEDIATE PAYLOAD URLS
  13. http://dreamwatchevent.com/wpadmins/Protected Client.js
  14. http://dreamwatchevent.com/wpadmins/Attack.jpg
  15.  
  16. INTERMEDIATE PAYLOAD FILE HASHES
  17. notapad.js
  18. 6f7fd86b0cd0c3886e56f953d578845b
  19.  
  20. Attack.jpg
  21. 2b0ee894d5f1092a38cd7be030f8fb12
  22.  
  23. REMCOS C2
  24. freightmgmt.duckdns.org:691
  25. https://194.5.98.207:691
  26.  
  27. SUPPORTING EVIDENCE
  28. https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
  29. https://app.any.run/tasks/9ef7784e-42c9-4281-b223-7efa49178baf/
  30.  
Advertisement
Add Comment
Please, Sign In to add comment