ExecuteMalware

2021-03-24 Remcos IOCs

Mar 24th, 2021
16,912
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.57 KB | None | 0 0
  1. THREAT IDENTIFICATION: REMCOS RAT
  2.  
  3. SUBJECTS OBSERVED
  4. ACH Remittance Advice-0032421
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Remittance Advice.xls
  10. 19eeb9f08b76b43bc18ebd0ace1881cd
  11.  
  12. PAYLOAD URL
  13. http://vendorcreditglobal.online/file/hut.js
  14. http://vendorcreditglobal.online/find/mac.jpg
  15.  
  16. PAYLOAD FILE HASHES
  17. Same file hash as hut.js
  18. rud.js
  19. a47b7104414e13a0a5f77692da5009dd
  20.  
  21. mac.jpg
  22. 90521b33d7e36758b945a49ddaf6a041
  23.  
  24. InstallUtil.exe
  25. bb85aa6d90a4157ed799257072b265ff
  26.  
  27. REMCOS C2
  28. daemontime.myq-see.com
  29. https:194.5.98.147:1698
Advertisement
Add Comment
Please, Sign In to add comment