ExecuteMalware

2021-07-07 IcedID IOCs

Jul 7th, 2021 (edited)
15,776
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.35 KB | None | 0 0
  1. THREAT IDENTIFICATION: ICEDID / BOKBOT
  2.  
  3. SUBJECTS OBSERVED
  4. Docusign - You documents are ready
  5. Docusign has been completed
  6. FWD: Documents follow up 7/08/21
  7. FWD: Docusign has been completed 07-08-2021
  8. Invoice 394NH IRS
  9. Please Docusign - Document - 7/8/21
  10. RE: Adopt Your Signature
  11. RE: Documents follow up 07/8
  12. RE: Docusign - You documents are ready
  13. Tsheets 39550-TLZ92j
  14.  
  15. SENDERS OBSERVED
  16.  
  17. MALDOC FILE NAMES
  18. ew19598.xlsb
  19. ew4257.xlsb
  20. ew21999.xlsb
  21. ew25355.xlsb
  22. ew21563.xlsb
  23.  
  24. MALDOC FILE HASHES
  25. 18e913202f8d4af799ee565f29c58864
  26. 4865f82d1dc3a18dbf22189898f14147
  27. a441609e07523bfa2fb671fd6376089f
  28. da4d2687b1fc5b27b5bd42cfba9db96b
  29. e39b4d9cdeb44d584a3c1937ee8fe2d8
  30.  
  31. ICEDID PAYLOAD DOWNLOAD URLS
  32. https://docusignsecpro.com/data/int64/sup/crv.dll
  33.  
  34. ICEDID PAYLOAD FILE HASHES
  35. crv.dll
  36. 3ddeea156606b2e5d19c86cedf3dec30
  37.  
  38. Renamed and downloaded to:
  39. C:\Users\Public\Libraries\AMD64glory.sys
  40. 3ddeea156606b2e5d19c86cedf3dec30
  41.  
  42. ICEDID C2/STAGING SERVER
  43. http://revedanstvy.bid/
  44.  
  45. SUPPORTING EVIDENCE
  46. https://app.any.run/tasks/338e0e56-e4f8-4ef1-a271-562e041091f4/
  47. https://tria.ge/210707-2dqxl3l9vx
Add Comment
Please, Sign In to add comment