Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #remcos #rat
- https://pastebin.com/kjv5E8Au
- previous_contact:
- 12/07/21 https://pastebin.com/ZYZarB9L
- 15/07/19 https://pastebin.com/ZxG6eRWM
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
- https://urlhaus.abuse.ch/browse/tag/remcos
- attack_vector
- --------------
- email > attach1 .rar > attach2 .rar (pwd) > exe1 > %temp%\2.exe > %userprofile%\sql\sql.exe > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Return-Path: <info@telecomds.online>
- Received: from telecomds.online (telecomds.online [80.78.254.28])
- From: Глушко Іван Кирилович <info@telecomds.online>
- Subject: Судова претензія за Вашим особовим рахунком # 368970468258859253 от: 06.02.2023
- Date: Sun, 5 Feb 2023 13:35:48 -0800
- Message-Id: <E1pOmfs-000Pdp-6C@mail.telecomds.online>
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 f1103f0e35b7b47f020f951f07a87c74275aacec6a2610690a0f80e34e8eae73
- File name судовий лист, інформація щодо заборгування.rar [ RAR compressed archive (v5.0) ]
- File size 534.64 KB (547476 bytes)
- SHA-256 5047f53e2e496b38b1a11bc856c79d6602fb28f7a0b16a4c4082845dee225677
- File name судовий лист, інформація щодо заборгування. pdf.rar [ RAR compressed archive (v5.0) password protected]
- File size 533.76 KB (546574 bytes)
- SHA-256 644f8bf83d861db06b736b1d5e541e35d3eae75a74d6f2561fa26a9a271a2c2b
- File name судовий лист, інформація щодо заборгування.pdf.exe
- File size 656 MB
- SHA-256 ca408a4f313a8dc8afe42b490e74b345d758bc319c0b5b251f03fed84e8deb0e
- File name 2.exe (sql.exe) [ PE32 executable for MS Windows (GUI) ]
- File size 476.00 KB (487424 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR email_attach
- C2 94.131.99.89:5222
- 94.131.99.56:5222
- 94.131.99.156:5222
- 101.99.91.158:5222
- 124.88.67.67:5222
- 178.23.190.252:8080
- 178.23.190.253:8080
- 178.23.190.254:8080
- 178.23.190.54:8080
- netwrk
- --------------
- 101.99.91.158 5222 TCP 49577 → 5222 [SYN]
- 124.88.67.67 5222 TCP 49579 → 5222 [SYN]
- 178.23.190.252 8080 TCP 49585 → 8080 [SYN]
- 178.23.190.253 8080 TCP 49586 → 8080 [SYN]
- 178.23.190.254 8080 TCP 49587 → 8080 [SYN]
- 178.23.190.54 8080 TCP 49600 → 8080 [SYN]
- 94.131.99.156 5222 TCP 49606 → 5222 [SYN]
- 94.131.99.56 5222 TCP 49584 → 5222 [SYN]
- 94.131.99.89 5222 TCP 49583 → 5222 [SYN]
- comp
- --------------
- sql.exe 3820 101.99.91.158 5222 ESTABLISHED
- sql.exe 3820 94.131.99.153 8080 ESTABLISHED
- sql.exe 3820 94.131.99.156 5222 ESTABLISHED
- sql.exe 3820 178.23.190.252 8080 ESTABLISHED
- sql.exe 3820 178.23.190.253 8080 ESTABLISHED
- sql.exe 3820 124.88.67.67 5222 ESTABLISHED
- sql.exe 3820 124.88.67.98 5222 ESTABLISHED
- sql.exe 3820 178.23.190.254 8080 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\судовий лист, інформація щодо заборгування.pdf.exe
- C:\tmp\2.exe
- C:\Users\operator\sql\sql.exe
- persist
- --------------
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 06.02.2023 15:03
- skype_upd c:\users\operator\sql\sql.exe 25.01.2023 13:44
- drop
- --------------
- %temp%\2.exe
- %userprofile%\sql\sql.exe
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/f1103f0e35b7b47f020f951f07a87c74275aacec6a2610690a0f80e34e8eae73/details
- https://www.virustotal.com/gui/file/5047f53e2e496b38b1a11bc856c79d6602fb28f7a0b16a4c4082845dee225677/details
- https://www.virustotal.com/gui/file/ca408a4f313a8dc8afe42b490e74b345d758bc319c0b5b251f03fed84e8deb0e/details
- https://analyze.intezer.com/analyses/da288060-eb42-4882-9ac7-291a299bb338
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement