VRad

#remcos_020924

Sep 2nd, 2024 (edited)
314
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.95 KB | None | 0 0
  1. #IOC #OptiData #VR #remcos #RAT #stego #pngbase64 #PowerShell #RegAsm
  2.  
  3. https://pastebin.com/j1ZGJxxU
  4.  
  5. previous_contact:
  6. 223/08/24 https://pastebin.com/VmpVnz6b
  7. 16/08/24 https://pastebin.com/AkHsxz6R
  8. 13/08/24 https://pastebin.com/VDVp6hSi
  9. 19/01/24 https://pastebin.com/EvXHfZUB
  10. 18/01/24 https://pastebin.com/FL2fX362
  11. 25/12/23 https://pastebin.com/D535PVm3
  12. 21/12/23 https://pastebin.com/samYnJq6
  13. 30/11/23 https://pastebin.com/aG6XyqHN
  14. 13/11/23 https://pastebin.com/tbRpiGG5
  15. 06/02/23 https://pastebin.com/kjv5E8Au
  16.  
  17. FAQ:
  18. https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
  19.  
  20. attack_vector
  21. --------------
  22. email attach .rar > .rar (pwd) > .bat > cmd > powershell > get bitbucket .jpg & .txt > RegAsm.exe > C2
  23.  
  24.  
  25. # # # # # # # #
  26. email_headers
  27. # # # # # # # #
  28. Date: Mon, 2 Sep 2024 10:51:51 +0200
  29. From: Господарський суд Одеської області <contact @diagjfl _fr>
  30. Subject: Повідомлення про виробництво щодо ТОВ _назва_жертви
  31. Reply-To: Господарський суд Одеської області <inbox @od _arbitr _gov _ua>
  32. Received: from ns0 _arobiz _pro ([185 _34 _32 _71]
  33. Received: from (unknown [217 _196 _98 _177])
  34. Message-ID: <20240902085152 _BA7402E00CF1 @mail _arobiz _pro>
  35.  
  36. # # # # # # # #
  37. files
  38. # # # # # # # #
  39. SHA-256 93b777a3bf5c868c9fec5465aa912f79e45589d136cb7e32e74c995ac80c8631
  40. File name Документи (СУД).rar
  41. File size 11.67 KB (11955 bytes)
  42.  
  43. SHA-256 17504af5f0b685f934404a49fe6ce392cdaa9717b70099635383d450708d3f89
  44. File name Документи (СУД).rar
  45. File size 11.20 KB (11470 bytes)
  46.  
  47. SHA-256 0b6ff11b6bb77a2b5fddd259c021c80096d681e955468e342435ab93d1743cd7
  48. File name Порядок денний до суду.bat
  49. File size 13.17 KB (13481 bytes)
  50.  
  51. SHA-256 3e243672f6c94dd0edc7e41d6ab0920b1cd174fe102c71ae73d013c552edd6e4
  52. File name new_image(1).jpg
  53. File size 4.71 MB (4942734 bytes)
  54.  
  55. SHA-256 1a1776acfbc3d21e48b87e7035f3f1180fbd94a5944c5346e447490cbcf474e9
  56. File name one.txt
  57. File size 683.94 KB (700356 bytes)
  58.  
  59. # # # # # # # #
  60. activity
  61. # # # # # # # #
  62.  
  63. PL_SCR bitbucket _org /hgdfhdfgd/test /downloads/ new_image.jpg? 11811735 [loader]
  64. bitbucket _org /hgdfhdfgd/test /downloads/ new_image.jpg? 14441723 [loader]
  65. bitbucket _org /sdgw/sdge /downloads/ one.txt [payload]
  66.  
  67. C2 101 _99 _93 _108
  68.  
  69.  
  70. netwrk
  71. --------------
  72. 185 _166 _143 _49 bitbucket _org 443 TLSv1.2 Client Hello (SNI=bitbucket _org)
  73. 54 _231 _170 _113 bbuseruploads _s3 _amazonaws _com 443 TLSv1.2 Client Hello
  74. 101 _99 _93 _108 2404 TCP 50738 → 2404 [SYN]
  75. 178 _237 _33 _50 geoplugin _net 80 HTTP GET /json .gp HTTP/1.1
  76.  
  77. comp
  78. --------------
  79. powershell.exe 185 _166 _143 _49
  80. powershell.exe 54 _231 _170 _113
  81. RegAsm.exe 101 _99 _93 _108
  82. RegAsm.exe 178 _237 _33 _50
  83.  
  84. proc
  85. --------------
  86. C:\Windows\system32\cmd.exe /c ""C:\Users\User01\Desktop\Порядок денний до суду.bat" "
  87. powershell "$codigo = . . .
  88. C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
  89.  
  90. persist
  91. --------------
  92. n/a
  93.  
  94. drop
  95. --------------
  96. C:\ProgramData\rmc\logs.dat
  97.  
  98. # # # # # # # #
  99. additional info
  100. # # # # # # # #
  101. botnet hst_one
  102. mutex gdrgfddghgfd-FLRWT9
  103.  
  104. # # # # # # # #
  105. VT & Intezer
  106. # # # # # # # #
  107. https://www.virustotal.com/gui/file/93b777a3bf5c868c9fec5465aa912f79e45589d136cb7e32e74c995ac80c8631/details
  108. https://www.virustotal.com/gui/file/17504af5f0b685f934404a49fe6ce392cdaa9717b70099635383d450708d3f89/details
  109. https://www.virustotal.com/gui/file/0b6ff11b6bb77a2b5fddd259c021c80096d681e955468e342435ab93d1743cd7/details
  110. https://www.virustotal.com/gui/file/3e243672f6c94dd0edc7e41d6ab0920b1cd174fe102c71ae73d013c552edd6e4/details
  111. https://www.virustotal.com/gui/file/1a1776acfbc3d21e48b87e7035f3f1180fbd94a5944c5346e447490cbcf474e9/details
  112.  
  113. VR
Add Comment
Please, Sign In to add comment