ExecuteMalware

2020-11-11 Ave Maria IOCs

Nov 11th, 2020
4,506
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.71 KB | None | 0 0
  1. THREAT ATTRIBUTION: AVEMARIA RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Shipping Invoice
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Shipping Invoice.xls
  10. ab521c63163bb8be0139319493cb5e89
  11.  
  12. AVE MARIA PAYLOAD URLS
  13. https://cutt.ly/WgV1bTC
  14. https://cape-eye.co.za/originalfile.exe
  15.  
  16. AVE MARIA PAYLOAD FILE HASHES
  17. originalfile.exe
  18. c0a63243c263bc36091e9d0de51e4baa
  19.  
  20. AVE MARIA C2
  21. 209.127.186.228:5200
  22.  
  23. resolves to:
  24. warzonecastro.ddns.net
  25.  
  26. SUPPORTING EVIDENCE
  27. https://urlhaus.abuse.ch/url/807237/
  28. https://app.any.run/tasks/85ddbdda-2fd0-484d-90f6-9ef55a8ea0c6/
  29. https://app.any.run/tasks/37e8edc3-4e05-40c3-a8ff-355da5f73564/
  30. https://twitter.com/peterkruse/status/1326418390383210496
Advertisement
Add Comment
Please, Sign In to add comment