ExecuteMalware

2020-11-10 AveMaria IOCs

Nov 10th, 2020
4,527
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.62 KB | None | 0 0
  1. THREAT ATTRIBUTION: AVEMARIA RAT
  2. (Attribution is not 100% certain)
  3.  
  4. SUBJECTS OBSERVED
  5. Shipping Invoice
  6.  
  7. SENDERS OBSERVED
  8.  
  9. MALDOC FILE HASHES
  10. Invoice.xls
  11. e57b69e23d20f2fa1a390c7bf0afce64
  12.  
  13. AVE MARIA PAYLOAD URLS
  14. https://cutt.ly/7gCwp0G
  15. https://cape-eye.co.za/Andfw7.exe
  16.  
  17. AVE MARIA PAYLOAD FILE HASHES
  18. Andfw7.exe
  19. 82fad720c1c6bf97c3157c2def0cf651
  20.  
  21. AVE MARIA C2
  22. 209.127.186.228:6606
  23.  
  24. SUPPORTING EVIDENCE
  25. https://urlhaus.abuse.ch/browse.php?search=cape-eye.co.za
  26. (shows AveMaria, Masslogger and NetWire delivered from the same domain)
  27.  
  28. https://app.any.run/tasks/286047a6-7591-476c-ba09-45c2e58f3148/
Advertisement
Add Comment
Please, Sign In to add comment