Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: SNAKE KEYLOGGER
- SUBJECTS OBSERVED
- (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES-TWO WAREHOUSES AND OTHERS - MARJAN INCREMENT PROGRAM TANAJIB GAS PLANT PROJECT - PACKAGES 09 AND 11
- SENDERS OBSERVED
- MALDOC FILE HASHES
- (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES.IMG
- cc2bcba266b5fa7bccaf7592df6c1837
- SNAKE KEYLOGGER PAYLOAD FILE HASHES
- (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES.exe
- 519f9833658acf4cbfc0139b990f1411
- STOLEN DATA EXFILTRATED VIA EMAIL TO:
- us2.smtp.mailhostbox.com:587
- EXFILTRATION EMAIL ADDRESSES
- From: [email protected]
- STRINGS IN MEMORY FOR MSBUILD.EXE
- 0x419ba1 (56): https://api.telegram.org/bot
- 0x419ce8 (52): http://checkip.dyndns.org/
- 0x419dd8 (52): https://freegeoip.app/xml/
- SUPPORTING EVIDENCE
- https://www.virustotal.com/gui/file/5e38e3d0a442ea94f31e31b53084f904ab45661dc50c9abec49c0a016dea64a4/detection
Add Comment
Please, Sign In to add comment