Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: AVEMARIA RAT
- (Attribution is not 100% certain)
- SUBJECTS OBSERVED
- Shipping Invoice
- SENDERS OBSERVED
- MALDOC FILE HASHES
- Invoice.xls
- e57b69e23d20f2fa1a390c7bf0afce64
- AVE MARIA PAYLOAD URLS
- https://cutt.ly/7gCwp0G
- https://cape-eye.co.za/Andfw7.exe
- AVE MARIA PAYLOAD FILE HASHES
- Andfw7.exe
- 82fad720c1c6bf97c3157c2def0cf651
- AVE MARIA C2
- 209.127.186.228:6606
- SUPPORTING EVIDENCE
- https://urlhaus.abuse.ch/browse.php?search=cape-eye.co.za
- (shows AveMaria, Masslogger and NetWire delivered from the same domain)
- https://app.any.run/tasks/286047a6-7591-476c-ba09-45c2e58f3148/
Advertisement
Add Comment
Please, Sign In to add comment