Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #remcos #RAT #stego #pngbase64 #PowerShell #RegAsm
- https://pastebin.com/j1ZGJxxU
- previous_contact:
- 223/08/24 https://pastebin.com/VmpVnz6b
- 16/08/24 https://pastebin.com/AkHsxz6R
- 13/08/24 https://pastebin.com/VDVp6hSi
- 19/01/24 https://pastebin.com/EvXHfZUB
- 18/01/24 https://pastebin.com/FL2fX362
- 25/12/23 https://pastebin.com/D535PVm3
- 21/12/23 https://pastebin.com/samYnJq6
- 30/11/23 https://pastebin.com/aG6XyqHN
- 13/11/23 https://pastebin.com/tbRpiGG5
- 06/02/23 https://pastebin.com/kjv5E8Au
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
- attack_vector
- --------------
- email attach .rar > .rar (pwd) > .bat > cmd > powershell > get bitbucket .jpg & .txt > RegAsm.exe > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Mon, 2 Sep 2024 10:51:51 +0200
- From: Господарський суд Одеської області <contact @diagjfl _fr>
- Subject: Повідомлення про виробництво щодо ТОВ _назва_жертви
- Reply-To: Господарський суд Одеської області <inbox @od _arbitr _gov _ua>
- Received: from ns0 _arobiz _pro ([185 _34 _32 _71]
- Received: from (unknown [217 _196 _98 _177])
- Message-ID: <20240902085152 _BA7402E00CF1 @mail _arobiz _pro>
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 93b777a3bf5c868c9fec5465aa912f79e45589d136cb7e32e74c995ac80c8631
- File name Документи (СУД).rar
- File size 11.67 KB (11955 bytes)
- SHA-256 17504af5f0b685f934404a49fe6ce392cdaa9717b70099635383d450708d3f89
- File name Документи (СУД).rar
- File size 11.20 KB (11470 bytes)
- SHA-256 0b6ff11b6bb77a2b5fddd259c021c80096d681e955468e342435ab93d1743cd7
- File name Порядок денний до суду.bat
- File size 13.17 KB (13481 bytes)
- SHA-256 3e243672f6c94dd0edc7e41d6ab0920b1cd174fe102c71ae73d013c552edd6e4
- File name new_image(1).jpg
- File size 4.71 MB (4942734 bytes)
- SHA-256 1a1776acfbc3d21e48b87e7035f3f1180fbd94a5944c5346e447490cbcf474e9
- File name one.txt
- File size 683.94 KB (700356 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR bitbucket _org /hgdfhdfgd/test /downloads/ new_image.jpg? 11811735 [loader]
- bitbucket _org /hgdfhdfgd/test /downloads/ new_image.jpg? 14441723 [loader]
- bitbucket _org /sdgw/sdge /downloads/ one.txt [payload]
- C2 101 _99 _93 _108
- netwrk
- --------------
- 185 _166 _143 _49 bitbucket _org 443 TLSv1.2 Client Hello (SNI=bitbucket _org)
- 54 _231 _170 _113 bbuseruploads _s3 _amazonaws _com 443 TLSv1.2 Client Hello
- 101 _99 _93 _108 2404 TCP 50738 → 2404 [SYN]
- 178 _237 _33 _50 geoplugin _net 80 HTTP GET /json .gp HTTP/1.1
- comp
- --------------
- powershell.exe 185 _166 _143 _49
- powershell.exe 54 _231 _170 _113
- RegAsm.exe 101 _99 _93 _108
- RegAsm.exe 178 _237 _33 _50
- proc
- --------------
- C:\Windows\system32\cmd.exe /c ""C:\Users\User01\Desktop\Порядок денний до суду.bat" "
- powershell "$codigo = . . .
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
- persist
- --------------
- n/a
- drop
- --------------
- C:\ProgramData\rmc\logs.dat
- # # # # # # # #
- additional info
- # # # # # # # #
- botnet hst_one
- mutex gdrgfddghgfd-FLRWT9
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/93b777a3bf5c868c9fec5465aa912f79e45589d136cb7e32e74c995ac80c8631/details
- https://www.virustotal.com/gui/file/17504af5f0b685f934404a49fe6ce392cdaa9717b70099635383d450708d3f89/details
- https://www.virustotal.com/gui/file/0b6ff11b6bb77a2b5fddd259c021c80096d681e955468e342435ab93d1743cd7/details
- https://www.virustotal.com/gui/file/3e243672f6c94dd0edc7e41d6ab0920b1cd174fe102c71ae73d013c552edd6e4/details
- https://www.virustotal.com/gui/file/1a1776acfbc3d21e48b87e7035f3f1180fbd94a5944c5346e447490cbcf474e9/details
- VR
Add Comment
Please, Sign In to add comment