Advertisement
ExecuteMalware

2020-02-20 Remcos IOCs

Feb 20th, 2020
2,883
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.79 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Regarding Job
  3.  
  4. SENDERS OBSERVED
  5. James Johnson <frank@topl3ss.com>
  6.  
  7. EMAIL BODY
  8. Hello,
  9. I'm James Johnson and I'm interested in a job.
  10. I've added a copy of my resume.
  11. Pass code is 1234
  12.  
  13. Looking forward to hearing back from you!
  14. --
  15. James Johnson
  16.  
  17. 467146582
  18.  
  19. PAYLOAD URL
  20. http://199.19.226.33/droptop1.bin
  21.  
  22. ADDITIONAL DOWNLOAD URLS
  23. https://drive.google.com/uc?export=download&id=1N8gVOM5p8Ubm1HwolChxHidT7YoN29EE
  24. https://doc-00-2k-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ln06597lsc5jdn6kl1qvrs9r9qoolh4m/1582237800000/04567802101573540432/*/1N8gVOM5p8Ubm1HwolChxHidT7YoN29EE?e=download
  25.  
  26. DOCUMENT FILE HASH
  27. f631424f4956da36d6c88857e612a910
  28.  
  29. EXE FILE HASH
  30. b5479869c1ae14084526161cc002036c
  31.  
  32. REMCOS C2
  33. http://47.245.32.229:2500
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement