Advertisement
ExecuteMalware

2021-08-12 Formbook IOCs

Aug 12th, 2021 (edited)
10,820
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.98 KB | None | 0 0
  1. THREAT ATTRIBUTION: UNKNOWN LOADER
  2.  
  3. SUBJECTS OBSERVED
  4. RE: FW:Product Enquiry/New Order
  5.  
  6. SENDERS OBSERVED
  7. info@djasfo.com
  8.  
  9. ATTACHED MALDOC FILE HASHES
  10. PO_61934N.docx
  11. 0e98cd71f0ca7b8ff758c1e67f03afb1
  12.  
  13. MALDOC DOWNLOAD URL
  14. https://linkr.uk/RsSuI
  15.  
  16. DOWNLOADED MALDOC FILE HASH
  17. f.wbk
  18. b69168abc6dbe5d2cccf07fdd06e1808
  19.  
  20. UNKNOWN LOADER PAYLOAD DOWNLOAD URL
  21. 192.3.222.161/fide/win32.exe
  22.  
  23. UNKNOWN LOADER PAYLOAD FILE HASH
  24. win32.exe
  25. 5da09caaae82f21d0eaca876d498ee03
  26.  
  27. This file is renamed and copied to C:\Users\Public:
  28. vbc.exe
  29. 5da09caaae82f21d0eaca876d498ee03
  30.  
  31. UNKNOWN LOADER C2
  32. No C2 traffic was observed
  33.  
  34. SUPPORTING EVIDENCE
  35. https://www.virustotal.com/gui/file/afc6b7fc520feb049954946e10cd3d43d55b2d4fe80b679af39c5106c87d54d3/details
  36. https://www.virustotal.com/gui/file/f8d61b3b3139138de0b00e3e729cce091391d3ac6049fff5a695224656abaff5/community
  37. https://app.any.run/tasks/bfc288a6-55bf-4b82-8942-6d8675b5d922/
  38. https://app.any.run/tasks/4c17f564-93dc-4ad9-8151-7808ddfd31d9/
  39.  
  40.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement