ExecuteMalware

2021-03-01 Dridex IOCs

Mar 1st, 2021
6,379
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.74 KB | None | 0 0
  1. THREAT IDENTIFICATION: DRIDEX
  2.  
  3. SUBJECTS OBSERVED
  4. Ocean Freight overdue invoice Of 03_01_2021
  5.  
  6. SENDERS OBSERVED
  7.  
  8. DOCUMENT FILE HASHES
  9. Statement_as_of_mar_01_2021.xlsm
  10. c974f73e438cdd56984019d3865ff90b
  11.  
  12. DRIDEX PAYLOAD URLS
  13. https://inovatechit.com/a8lkv5.zip
  14.  
  15. DRIDEX PAYLOAD FILE HASH
  16. a8lkv5.zip
  17. 2b64b8df419b95739f4ee8c19c9eebea
  18.  
  19. which is renamed to:
  20. akbjdwr.dll
  21. 2b64b8df419b95739f4ee8c19c9eebea
  22.  
  23. DRIDEX C2s
  24. https://77.220.64.146:443
  25. https://85.25.134.43:8172
  26. https://213.208.134.178:6516
  27.  
  28. SUPPORTING EVIDENCE
  29. https://urlhaus.abuse.ch/browse.php?search=https%3A%2F%2Finovatechit.com%2Fa8lkv5.zip
  30. https://www.virustotal.com/gui/url/61cb3cfe61d68502c02034b23c5de7703fb87e47349c5037ed1d9c7699e7f5bb/detection
  31.  
Advertisement
Add Comment
Please, Sign In to add comment