Advertisement
ExecuteMalware

2021-02-17 Remcos IOCs - 2nd

Feb 17th, 2021
4,357
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.55 KB | None | 0 0
  1. THREAT IDENTIFICATION: REMCOS
  2.  
  3. SENDERS OBSERVED
  4. CitiBank_EFT-advice@Remit-Citi.com
  5.  
  6. MALDOC FILE HASHES
  7. Remittance Advice.xls
  8. 571f988258963aff38ef1bd06a36bcaa
  9.  
  10. JAVASCRIPT LOADER URL
  11. http://augustair.com/log/remit/edi.js
  12.  
  13. JAVASCRIPT LOADER FILE HASH
  14. edi.js
  15. 5f82fde65dfd751c2b602541e36ae6d7
  16.  
  17. Renamed to:
  18. outlook.js
  19. 5f82fde65dfd751c2b602541e36ae6d7
  20.  
  21. PAYLOAD URL
  22. http://augustair.com/log/remit/edi.jpg
  23.  
  24. PAYLOAD FILE HASH
  25. edi.jpg
  26. f7c5a6c6a3ddbe780d9d8bfe36911557
  27.  
  28. REMCOS C2
  29. I did not see any C2 traffic - I only let it run for a short time.
  30.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement