ExecuteMalware

2021-07-29 Raccoon Stealer IOCs

Jul 29th, 2021
15,310
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.91 KB | None | 0 0
  1. THREAT IDENTIFICATION: RACCOON STEALER
  2.  
  3. SUBJECTS OBSERVED
  4. Contact Submission
  5.  
  6. SENDERS OBSERVED
  7.  
  8. EMAIL BODY
  9. name: Mike
  10. message: Good morning, please pay the invoice. The invoice is
  11. available at https://cutt.ly/invoice_37223_2021 Best regards, Mike
  12.  
  13. RACCOON STEALER PAYLOAD DOWNLOAD URLS
  14. https://cutt.ly/invoice_37223_2021
  15.  
  16. https://ifirma.tw/pobierz/faktura-77_2021-3.pdf.exe
  17.  
  18. RACCOON STEALER PAYLOAD FILE HASHES
  19. faktura-77_2021-3.pdf.exe
  20. f7ba0f7a61b8b51a5e1823d5fd274d12
  21.  
  22. RACCOON STEALER C2
  23. http://34.141.84.7//l/f/AwR78noBagrSXdgRI6mK/2b5e22c8234245ec15224617bcd1d3d2815032f7
  24. http://34.141.84.7//l/f/AwR78noBagrSXdgRI6mK/d9f2d1eed65e7bf9f8f20e8047035ac98c2f99d4
  25.  
  26. SUPPORTING EVIDENCE
  27. https://www.virustotal.com/gui/file/97230d986df3ea5ab1a95966a7cd14ff73744912d34edb7a72776b78440d9293/detection
  28. https://app.any.run/tasks/a8167c48-857a-4a27-860f-d3569db25b25/
Advertisement
Add Comment
Please, Sign In to add comment