Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: REMCOS
- SUBJECTS OBSERVED
- Payment Advice Notification
- SENDERS OBSERVED
- JPM Chase Payment Notification <[email protected]>
- MALDOC FILE HASHES
- ACH Payment.xlsm
- 40e73282c0207d2975fa3acaf2989cd2
- Protected Client.vbs
- 2ffe7c088d780874fef08e0a10783c26
- Attack.jpg
- 904606da0668534602d198c51cc4103c
- MALDOC DOWNLOAD URLs
- http://oficina24.online/kingman/Protected Client.vbs
- PAYLOAD URL
- https://oficina24.online/king/hlobnm/good/youuryt/yuotoob/doogrty/ruoytr/root/okaytogo/Attack.jpg
- REMCOS C2
- srvr2.callofdutyserver.pw
- EMAIL BODY
- JPMorgan Chase
- This is a secure, encrypted message.
- Desktop Users:
- Open the attachment (Payment Advice.xlsm) and follow the instructions.
- Mobile Users:
- Open the attachment (Payment Advice.xlsm) on your PC and follow the instructions
- Need Help?
- Personal Security Image
- Your personalized image for:
- This personal security image will appear on secure email to you. If it's missing or unrecognized, please contact customer support. Learn more
- Disclaimer: This email and any attachments are confidential and for the sole use of the recipients. If you have received this email in error please notify the sender.
- Email Security Powered by Voltage IBE(tm)
- Copyright © 2015 JPMorgan Chase & Co. All rights reserved
Add Comment
Please, Sign In to add comment