ExecuteMalware

2021-05-27 IcedID IOCs

May 27th, 2021
16,835
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.32 KB | None | 0 0
  1. THREAT IDENTIFICATION: ICEDID
  2.  
  3. SENDERS OBSERVED
  4.  
  5. FORM CONTENTS
  6. Hi!
  7.  
  8. My name is Melody.
  9.  
  10. Your website or a website that your company hosts is infringing on a copyright protected images owned by myself.
  11.  
  12. Take a look at this report with the hyperlinks to my images you used at www.<yourdomain>.com and my previous publications to get the proof of my copyrights.
  13.  
  14. Download it now and check this out for yourself:
  15.  
  16. https://sites.google.com/view/234387234572004834/d/download/0/shared/files?fileID=140612158322889214
  17.  
  18. I believe you've deliberately violated my rights under 17 U.S.C. Section 101 et seq. and could be liable for statutory damages as high as $130,000 as set-forth in Sec. 504(c)(2) of the Digital millennium copyright act (”DMCA”) therein.
  19.  
  20. This message is official notice. I demand the elimination of the infringing materials described above. Please be aware as a service provider, the Digital Millennium Copyright Act demands you, to remove and terminate access to the copyrighted materials upon receipt of this notification letter. In case you do not stop the utilization of the aforementioned copyrighted content a legal action can be initiated against you.
  21.  
  22. I have a strong faith belief that use of the copyrighted materials referenced above as presumably violating is not permitted by the copyright owner, its legal agent, as well as laws.
  23.  
  24. I swear, under consequence of perjury, that the information in this letter is accurate and that I am the legal copyright owner or am certified to act on behalf of the proprietor of an exclusive right that is allegedly infringed.
  25.  
  26. Regards,
  27. Melody Lynn
  28.  
  29. 05/27/2021
  30.  
  31. MALDOC DOWNLOAD URL
  32. https://sites.google.com/view/234387234572004834/d/download/0/shared/files?fileID=140612158322889214
  33.  
  34. MALDOC FILE HASHES
  35. Stolen Images Evidence.zip
  36. ddfc4e91a1750dc184dad19cab97c3fe
  37.  
  38. Stolen Images Evidence.js
  39. 8a7efa40b42b6de785f13dcd505a0b1a
  40.  
  41. PAYLOAD DOWNLOAD URLS
  42. http://bediloper.top/034g100/index.php
  43. http://bediloper.top/034g100/main.php
  44.  
  45. main.php
  46. a8737302ebec172bbf8f1dfe30a81b64
  47.  
  48. RYDTKuh.dat
  49. 8dabd9a48c5b96cc629d72cc9b0c0d0d
  50.  
  51. They're both 64-bit .dll files
  52.  
  53. ICEDID C2s
  54. http://lascakatheather.top/
  55. 172.67.198.112
  56.  
  57. SUPPORTING EVIDENCE
  58. https://www.microsoft.com/security/blog/2021/04/09/investigating-a-unique-form-of-email-delivery-for-icedid-malware/
Advertisement
Add Comment
Please, Sign In to add comment