Rewterz Threat Alert – Remcos RAT – Active IOCs - Rewterz
Tags
attack-pattern: | Malware - T1587.001 Malware - T1588.001 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | 1de39f70-f637-4ce4-908f-64aad86527a9 |
Fingerprint | 85b62b4d8ecfafc6 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Aug. 24, 2022, 11:53 a.m. |
Added to db | Dec. 19, 2024, 10:43 a.m. |
Last updated | Dec. 19, 2024, 8:51 p.m. |
Headline | Rewterz Threat Alert – Remcos RAT – Active IOCs |
Title | Rewterz Threat Alert – Remcos RAT – Active IOCs - Rewterz |
Detected Hints/Tags/Attributes | 15/1/18 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 53 | machine.it |
|
Details | Domain | 2 | nvoicepay-ach.com |
|
Details | Domain | 2 | mckinneytighe.com |
|
Details | 2 | remittance@nvoicepay-ach.com |
||
Details | md5 | 2 | 135a1b45054fd8c36e854fb696d7391a |
|
Details | md5 | 2 | c135c2dad6b8d014bfd512fd94d31200 |
|
Details | md5 | 2 | 5a060aa2e0e82ee0b03b65ce9ed52c2f |
|
Details | md5 | 2 | 4b04a1aed8a1398e7d0139f367917d8e |
|
Details | sha1 | 1 | 80e56aad8cf5281d4374ae3b3f99ae7bd3f46198 |
|
Details | sha1 | 1 | 9769b8c4d5e9fe2c04044f80410dac8fa079a9f8 |
|
Details | sha1 | 1 | c8ef799fb03c6ae42b6f7590d7733c80f54c7c5a |
|
Details | sha1 | 1 | c38842cddf2bfae8d84a843dc876e4432cd4b734 |
|
Details | sha256 | 1 | 7e59886a1137a4e857507cc61b150d5637ff71b09af43deeb70d1c9644ce465e |
|
Details | sha256 | 1 | e805a1a3bfff781d5f38af1cef377669b44354c40a4edbe5d0aad6c1e2d6e406 |
|
Details | sha256 | 1 | a224dcb4bd0ac20f6241885b3cd0ca5f552dc6ddcca360d27204bd9c47cec4a7 |
|
Details | sha256 | 1 | 90a5c56cc9847dde12d4fd035f90f5afcc6235336d55e16c48e943365dfe85c2 |
|
Details | Url | 2 | http://mckinneytighe.com/newmon/calc/attack.jpg |
|
Details | Url | 2 | http://mckinneytighe.com/newmon/calc/client.vbs |