Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: AVEMARIA RAT
- SUBJECTS OBSERVED
- Shipping Invoice
- SENDERS OBSERVED
- MALDOC FILE HASHES
- Shipping Invoice.xls
- ab521c63163bb8be0139319493cb5e89
- AVE MARIA PAYLOAD URLS
- https://cutt.ly/WgV1bTC
- https://cape-eye.co.za/originalfile.exe
- AVE MARIA PAYLOAD FILE HASHES
- originalfile.exe
- c0a63243c263bc36091e9d0de51e4baa
- AVE MARIA C2
- 209.127.186.228:5200
- resolves to:
- warzonecastro.ddns.net
- SUPPORTING EVIDENCE
- https://urlhaus.abuse.ch/url/807237/
- https://app.any.run/tasks/85ddbdda-2fd0-484d-90f6-9ef55a8ea0c6/
- https://app.any.run/tasks/37e8edc3-4e05-40c3-a8ff-355da5f73564/
- https://twitter.com/peterkruse/status/1326418390383210496
Advertisement
Add Comment
Please, Sign In to add comment