Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #agenttesla #RAT #passwdstealer #FTP
- https://pastebin.com/pma5MQAW
- previous_contact:
- 12/06/20 https://pastebin.com/SKNts0Es
- 29/10/19 https://pastebin.com/RinpBPvy
- 03/09/19 https://pastebin.com/zhJvDz8M
- 09/01/19 https://pastebin.com/MdDfZDdb
- 16/10/18 https://pastebin.com/d5DxTRrB
- 04/10/18 https://pastebin.com/JYShuXn4
- 11/10/18 https://pastebin.com/bkCSvJvM
- FAQ:
- https://radetskiy.wordpress.com/2018/10/19/ioc_agenttesla_111018/
- attack_vector
- --------------
- email attach .png > URL link > 7zip > exe
- email_headers
- --------------
- Received: from rin43152.imocstudio.com (rin43152.imocstudio.com [82.223.43.152])
- Received: from webmail.ferrallados.es (localhost.localdomain [127.0.0.1])
- Date: Mon, 15 Jun 2020 04:14:01 +0100
- From: Сьюзан Бойко <[email protected]>
- To: undisclosed-recipients:;
- Subject: Новий ордер на купівлю #15060012
- User-Agent: Roundcube Webmail/1.4.3
- X-Sender: [email protected]
- Return-Path: [email protected]
- files
- --------------
- SHA-256 0d1dbc780abe80489dd8661ab0d3de7f1915e0ea52d17705cbbac43921e420f1
- File name 15060012.7z [7-zip archive data, version 0.4]
- File size 237.17 KB (242858 bytes)
- SHA-256 c0beca8181828e29cf435168b33e8d535f6a84be95e9f88b739867e7a4a1c11b
- File name 15060012.exe [ .NET executable ]
- File size 614.50 KB (629248 bytes)
- SHA-256 978a4093058aa2ebf05dc353897d90d950324389879b57741b64160825b5ec0e
- File name AddInProcess32.exe [ .NET executable ]
- File size 41.09 KB (42080 bytes)
- activity
- **************
- PL_SCR
- https://www.mediafire.com/file/c3pe7lverm3bpsp/15060012.7z/file
- C2
- 77.88.21.158:587 smtp.yandex{.} com
- netwrk
- --------------
- 77.88.21.158 smtp.yandex.com
- comp
- --------------
- AddInProcess32.exe 3268 TCP 77.88.21.158 587 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\15060012.exe
- C:\tmp\AddInProcess32.exe
- persist
- --------------
- n/a
- drop
- --------------
- C:\tmp\AddInProcess32.exe
- # # #
- https://www.virustotal.com/gui/file/0d1dbc780abe80489dd8661ab0d3de7f1915e0ea52d17705cbbac43921e420f1/details
- https://www.virustotal.com/gui/file/c0beca8181828e29cf435168b33e8d535f6a84be95e9f88b739867e7a4a1c11b/details
- https://www.virustotal.com/gui/file/978a4093058aa2ebf05dc353897d90d950324389879b57741b64160825b5ec0e/details
- https://analyze.intezer.com/#/analyses/8b154c71-5e67-4405-af7d-661a24b78383
- VR
Add Comment
Please, Sign In to add comment