ExecuteMalware

201-08-05 Agent Tesla IOCs

Aug 5th, 2021 (edited)
11,213
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.62 KB | None | 0 0
  1. THREAT IDENTIFICATION: AGENT TESLA
  2.  
  3. SUBJECTS OBSERVED
  4. FW:Eliecer López Barbosa: RV: CIF Colombia CARTAGENA Order.
  5.  
  6. SENDERS OBSERVED
  7. ghulamhussain@alphasolar.com
  8.  
  9. MALDOC FILE HASHES
  10. Contracts-Tender080052021-signed.zip
  11. 1e75b61a3d486625868cf51241c0c6a5
  12.  
  13. AGENT TESLA PAYLOAD FILE HASHES
  14. Contracts-Tender080052021-signed.exe
  15. 2f155183bbc4a2e0cb5b0af94e1a89e9
  16.  
  17. Renamed to:
  18. zISUu.exe
  19. 2f155183bbc4a2e0cb5b0af94e1a89e9
  20.  
  21. AGENT TESLA FTP DESTINATION
  22. ftp://ftp.winners.jumie-acrylic.com/CO_analyst-WIN7PC_2021_08_05_11_11_33.zip
  23.  
  24. EXFILTRATION INFORMATION
  25. Sender: slime@winners.jumie-acrylic.com
  26. Password: P@55W0RDs2021
  27.  
  28.  
Add Comment
Please, Sign In to add comment