ExecuteMalware

2021-02-10 Dridex IOCs

Feb 10th, 2021 (edited)
6,029
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.62 KB | None | 0 0
  1. THREAT ATTRIBUTION: DRIDEX
  2.  
  3. SUBJECTS OBSERVED
  4. Updated Invoice(s) with Adjustment
  5.  
  6. SENDERS OBSERVED
  7.  
  8. DOCUMENT FILE HASHES
  9. INV3104508191.xlsm
  10. 087ab72bddf5ddc2b92322833a478dd7
  11.  
  12. DRIDEX PAYLOAD URLS
  13. https://coachboom.mhtechnologies.us/cpwjurqt.zip
  14.  
  15. DRIDEX PAYLOAD FILE HASH
  16. cpwjurqt.zip
  17. dc0034ec0c1c3c74e3396a8313ebde01
  18.  
  19. It's really a .dll file not a .zip file
  20. cnxlsycx.dll
  21. dc0034ec0c1c3c74e3396a8313ebde01
  22.  
  23. DRIDEX C2s
  24. 77.220.64.132:443
  25. 212.227.53.240:5037
  26.  
  27. SUPPORTING EVIDENCE
  28. https://app.any.run/tasks/298327f5-1565-4d8b-b120-2fd792ad0ce0/
  29. https://urlhaus.abuse.ch/url/998960/
Add Comment
Please, Sign In to add comment