ExecuteMalware

2020-08-10 TA505 IOCs

Aug 10th, 2020
4,211
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.99 KB | None | 0 0
  1. THREAT ATTRIBUTION: TA505
  2.  
  3. SUBJECTS OBSERVED
  4. Pension certificates
  5.  
  6. SENDERS OBSERVED
  7. Roger[.]Dickenson@acse77[.]fr
  8. Roger[.]Dickenson@piccionigroup[.]it
  9. Roger[.]Dickenson@24telekom[.]com
  10. Roger[.]Dickenson@novotny-reality[.]cz
  11. Roger[.]Dickenson@nanumsem[.]com
  12. Roger[.]Dickenson@koperasimadani[.]co[.]id
  13. Roger[.]Dickenson@ttr[.]com[.]tr
  14. Roger[.]Dickenson@satius[.]com[.]ar
  15. Roger[.]Dickenson@goline[.]com[.]cn
  16. Roger[.]Dickenson@grauvogl[.]org
  17. Roger[.]Dickenson@transatlantic[.]is
  18.  
  19. MALDOC LANDING PAGE URLS
  20. hxxp://eduthermas[.]sk/vz0s4[.]html
  21. hxxp://falcon1[.]net/~carolb/eedvmpj[.]html
  22. hxxp://jqtrias[.]com/v61vd[.]html
  23. hxxp://lewell[.]fr/2au7x[.]html
  24. hxxp://razor[.]arnes[.]si/~osjkranjkr/h2j6x2n[.]html
  25. hxxp://verkeersovertredingen[.]nl/ozkk1g5[.]html
  26. hxxp://www[.]newmedia[.]plus[.]com/bu2a8o[.]html
  27. hxxp://www[.]scottofyork[.]plus[.]com/ouwd7q[.]html
  28.  
  29. MALDOC DISTRIBUTION URLS
  30. hxxps://dl[.]river-store[.]com/
  31. (currently down)
  32.  
  33. SUPPORTING EVIDENCE
  34. https://urlhaus.abuse.ch/url/427135/
Add Comment
Please, Sign In to add comment