ExecuteMalware

2021-07-14 Remcos IOCs

Jul 14th, 2021
15,431
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.52 KB | None | 0 0
  1. THREAT IDENTIFICATION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Separate Remittance Advice: paper document number - 96972
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Chase Payment Advice_96972.docm
  10. 784a11e7c537bfe34e5287708cb0cb77
  11.  
  12. INTERMEDIATE PAYLOAD URLS
  13. http://192.227.158.111/jun.js
  14. http://192.227.158.111/fit.jpg
  15.  
  16. INTERMEDIATE PAYLOAD FILE HASHES
  17. jun.js
  18. ceb58144b89ea3c7d42611b451e21cb7
  19.  
  20. fit.jpg
  21. fdbac45ef0ed9de668c0740bd80e1379
  22.  
  23. REMCOS C2
  24. twistednerd.dvrlists.com
  25. https://141.98.102.243:41078
Advertisement
Add Comment
Please, Sign In to add comment