ExecuteMalware

2021-02-08 Likely Ave Maria RAT IOCs

Feb 8th, 2021
4,221
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.48 KB | None | 0 0
  1. THREAT ATTRIBUTION: LIKELY AVEMARIA RAT
  2.  
  3. SUBJECTS OBSERVED
  4. Request quotation for SPARE PARTS provision
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. PO 213409701.xlsx
  10. a17143ea703ed4fef934fa1d8c8c413c
  11.  
  12. SPARE PARTS Drawing.xlsx
  13. a17143ea703ed4fef934fa1d8c8c413c
  14.  
  15. AVE MARIA PAYLOAD URLS
  16. https://cutt.ly/Fkz48wO
  17. http://stdykungcommunicstcd.dns.army/kungdoc/winlog.exe
  18.  
  19. AVE MARIA PAYLOAD FILE HASHES
  20. winlog.exe
  21. e04e30ce82c10d8e4fe03ed0cdfa381a
  22.  
  23. AVE MARIA C2
  24. N/A
Advertisement
Add Comment
Please, Sign In to add comment