ExecuteMalware

201-08-05 Agent Tesla IOCs

Aug 5th, 2021 (edited)
15,070
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.62 KB | None | 0 0
  1. THREAT IDENTIFICATION: AGENT TESLA
  2.  
  3. SUBJECTS OBSERVED
  4. FW:Eliecer López Barbosa: RV: CIF Colombia CARTAGENA Order.
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Contracts-Tender080052021-signed.zip
  10. 1e75b61a3d486625868cf51241c0c6a5
  11.  
  12. AGENT TESLA PAYLOAD FILE HASHES
  13. Contracts-Tender080052021-signed.exe
  14. 2f155183bbc4a2e0cb5b0af94e1a89e9
  15.  
  16. Renamed to:
  17. zISUu.exe
  18. 2f155183bbc4a2e0cb5b0af94e1a89e9
  19.  
  20. AGENT TESLA FTP DESTINATION
  21. ftp://ftp.winners.jumie-acrylic.com/CO_analyst-WIN7PC_2021_08_05_11_11_33.zip
  22.  
  23. EXFILTRATION INFORMATION
  24. Password: P@55W0RDs2021
  25.  
  26.  
Add Comment
Please, Sign In to add comment