Phishing Attacks 29_4_2021
(1)
| Sender ip | 185.222.58.152 | 
| From  | "Account"
  <inginer@ecolux.md>" | 
| Subject | "Statement of account -invoices
  No. 10132870" | 
| Attachment | "DUE INVOICES.zip" | 
| MD5 | 3402fa1649793be014907c9e7538cb90 | 
| SHA256 | 7fa3827e99f28c847cee92b9753e5978069868f9d7fc447c846bfbeafae43666 | 
| Family  | AgentTesla | 
(2)
| Sender ip | 199.10.31.237 | 
| From  | "Escribano@coscosh.com" | 
| Subject | "PRODUCT CONFIRMATION
  REQUEST" | 
| Attachment | "Sales order 191923.gz" | 
| MD5 | a1c19acee1b59ff6530dc5caadbcf356 | 
| SHA256 | 304b4c9957a518e5b1b765f84557372160266bf55a65963a1b7336ccdf34a084 | 
| Family  | AgentTesla | 
(3)
| Sender ip | 103.133.105.111 | 
| From  | "Jiangchuan Junguan
  <sales@sun-yuan.com>" | 
| Subject | "NEW ORDER INQUIRY_B1020289" | 
| Attachment | "NEW ORDER
  INQUIRY_B1020289.pdf.gz" | 
| MD5 | a24201e99541561a5ef93b54dfa8badd | 
| SHA256 | f94e98462af69853708dcc3e752dafeb42995ddb322741f3f958460a210c164c | 
| Family  | Formbook | 
(4)
| Sender ip | 203.159.80.162 | 
| From  | "Mohammed Hanif <manager@gcacorperationllc.com>" | 
| Subject | "(NGCP) Pipeline PROJECT -
  TA-725638 - DK-RH-HRDH - HEADER PLATFORM TYPE 1-16-47M_MARKING &
  FABRICATION DRAWINGS WITH FULL PACKAGE FOR CONSTRUCTION" | 
| Attachment | "NGCP Pipeline PROJECT TA 725638
  DK RH HRDH HEADER PLATFORM TYPE 1 16 47M MARKING & FABRICATION DRAWINGS
  WITH FULL PACKAGE FOR CONSTRUCTION (2).zip" | 
| MD5 | 3cc25b5305da49f00e7bfb3ba19caa1c | 
| SHA256 | 32f8065d637ce4e96a8c56dd0a5a9f41fb8c443ffe913c69d2e422e304908c2c | 
| Family  | Unknown | 
(5)
| Sender ip | 185.222.58.152 | 
| From  | "Account"
  <inginer@ecolux.md>" | 
| Subject | "Statement of account" | 
| Attachment | "SOA.zip" | 
| MD5 | b5155ad7c3debabeece655d1852095c4 | 
| SHA256 | 90c1d680a867af042eaf60ba32ab1a651ee270a3fbad7cf806681d6b74138d33 | 
| Family  | AgentTesla | 
(6)
| Sender ip | 199.10.31.238 | 
| From  | "ross.kohlbeck@amerhart.com" | 
| Subject | "Re: RE: Request For PI" | 
| Attachment | "Order Items.gz" | 
| MD5 | efd35f97c09fdcc7cc4114fab49a87b9 | 
| SHA256 | 40cec6cc82800698e57005753fa5bc7a379a64b3a3ed15efc6ad357604edd7ea | 
| Family  | AgentTesla | 
If you wanna learn malware analysis you can check my YouTube channel I'm trying publish analysis of malware and some methods to analysis malwares.
Please don't forgot subscribe my channel Than you ♥
YouTube channel
https://www.youtube.com/channel/UCParXHaBXBmqRdHuVUg21pA
 
Comments
Post a Comment