Advertisement
ExecuteMalware

2021-08-13 Remcos IOCs

Aug 13th, 2021
11,191
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. THREAT ATTRIBUTION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. PAYMENT REMITTANCE ADVICE
  5.  
  6. SENDERS OBSERVED
  7. hg7790@daum.net
  8.  
  9. MALDOC FILE HASHES
  10. ACH Remittance.xls
  11. 3d60d0c1b933856982737fc3b079ff00
  12.  
  13. INTERMEDIATE PAYLOAD URLS
  14. http://dreamwatchevent.com/wpadmins/Protected Client.js
  15. http://dreamwatchevent.com/wpadmins/Attack.jpg
  16.  
  17. INTERMEDIATE PAYLOAD FILE HASHES
  18. notapad.js
  19. 6f7fd86b0cd0c3886e56f953d578845b
  20.  
  21. Attack.jpg
  22. 2b0ee894d5f1092a38cd7be030f8fb12
  23.  
  24. REMCOS C2
  25. freightmgmt.duckdns.org:691
  26. https://194.5.98.207:691
  27.  
  28. SUPPORTING EVIDENCE
  29. https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
  30. https://app.any.run/tasks/9ef7784e-42c9-4281-b223-7efa49178baf/
  31.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement