ExecuteMalware

2020-08-13 TA505 IOCs

Aug 13th, 2020
2,899
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.56 KB | None | 0 0
  1. THREAT ATTRIBUTION: TA505
  2.  
  3. SUBJECTS OBSERVED
  4. PLEASE READ: Important new Guidance Document - REVISED Privacy Policy
  5. Updated Finance Dept. Assignments
  6.  
  7. SENDERS OBSERVED
  8. aleksandr[.]koivistoinen@idavesi[.]ee
  9. contact@camping-romarin[.]com
  10. info@erenhasgroup[.]com
  11. kdsouza@capital-corp[.]com[.]uy
  12. kdsouza@clearcutcomputing[.]com
  13. kdsouza@etrog[.]net[.]il
  14. kdsouza@flatschart[.]at
  15. kdsouza@grupoep[.]es
  16. kdsouza@methylcorp[.]com
  17. kdsouza@pacific-regency[.]com
  18. kdsouza@paisagismopenseverde[.]com[.]br
  19. kdsouza@saude[.]mg[.]gov[.]br
  20. kdsouza@songhai[.]org
  21. kdsouza@teppanyaki-sawafuji[.]com
  22. kdsouza@ug-jezewo[.]lo[.]pl
  23. kdsouza@vander[.]co[.]uk
  24. orders@huastecagrill[.]com
  25. smart@mail[.]pmf[.]tw
  26.  
  27. MALDOC FILE HASH
  28. None
  29.  
  30. PAYLOAD FILE HASH
  31. None
  32.  
  33. MALDOC LANDING PAGE URLS
  34. hxxp://abi83-schramberg[.]de/p6nawpw[.]html
  35. hxxp://creditperformance[.]com[.]br/3dawp2[.]html
  36. hxxp://creditperformance[.]com[.]br/yt2f[.]html
  37. hxxp://mcsgrp[.]com/gtzkt[.]html
  38. hxxp://mwt[.]net/~blainee/6lim[.]html
  39. hxxp://papageienseite[.]de/5fas[.]html
  40. hxxp://petzel[.]be/rlcgklh[.]html
  41. hxxp://sauna-verdeclub[.]jp/5g2bx7n[.]html
  42. hxxp://sauna-verdeclub[.]jp/ilew[.]html
  43. hxxp://staceydodge[.]com/jio7ohc[.]html
  44. hxxp://tomsonguitars[.]co[.]uk/nk0j7r[.]html
  45. hxxp://travelhub[.]com[.]sg/psi50zi[.]html
  46. hxxp://www[.]skegness[.]net/jr7ad[.]html
  47.  
  48. MALDOC DISTRIBUTION URLS
  49. Directs here to get the xls file:
  50. hxxps://dl1[.]tremd-space[.]com/?hfjkdnv-djdjueu733-dnfhdf738-df5-6-7-676dgfgfg-445-01
  51. hxxps://dw[.]long-space[.]com/?hdhgjkfd-oiewourour-395-039-jfk-39485-swrkf
  52.  
  53. TA505 C2s
  54. transff-reddon[.]com
Add Comment
Please, Sign In to add comment