ExecuteMalware

2021-08-12 Formbook IOCs

Aug 12th, 2021 (edited)
14,734
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.98 KB | None | 0 0
  1. THREAT ATTRIBUTION: UNKNOWN LOADER
  2.  
  3. SUBJECTS OBSERVED
  4. RE: FW:Product Enquiry/New Order
  5.  
  6. SENDERS OBSERVED
  7.  
  8. ATTACHED MALDOC FILE HASHES
  9. PO_61934N.docx
  10. 0e98cd71f0ca7b8ff758c1e67f03afb1
  11.  
  12. MALDOC DOWNLOAD URL
  13. https://linkr.uk/RsSuI
  14.  
  15. DOWNLOADED MALDOC FILE HASH
  16. f.wbk
  17. b69168abc6dbe5d2cccf07fdd06e1808
  18.  
  19. UNKNOWN LOADER PAYLOAD DOWNLOAD URL
  20. 192.3.222.161/fide/win32.exe
  21.  
  22. UNKNOWN LOADER PAYLOAD FILE HASH
  23. win32.exe
  24. 5da09caaae82f21d0eaca876d498ee03
  25.  
  26. This file is renamed and copied to C:\Users\Public:
  27. vbc.exe
  28. 5da09caaae82f21d0eaca876d498ee03
  29.  
  30. UNKNOWN LOADER C2
  31. No C2 traffic was observed
  32.  
  33. SUPPORTING EVIDENCE
  34. https://www.virustotal.com/gui/file/afc6b7fc520feb049954946e10cd3d43d55b2d4fe80b679af39c5106c87d54d3/details
  35. https://www.virustotal.com/gui/file/f8d61b3b3139138de0b00e3e729cce091391d3ac6049fff5a695224656abaff5/community
  36. https://app.any.run/tasks/bfc288a6-55bf-4b82-8942-6d8675b5d922/
  37. https://app.any.run/tasks/4c17f564-93dc-4ad9-8151-7808ddfd31d9/
  38.  
  39.  
Advertisement
Add Comment
Please, Sign In to add comment