PULSE NAME
Retefe Banking Trojan
WHITE StreamMiningEx 2023-12-06 Modified: 2023-12-06
17
IOCs
MEDIUM VOLUME
Indicators of Compromise (17)
All FileHash-SHA256 domain URL YARA
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 a7087592f6f91f9bde54a855fb7b41f1114734533b9b681a918ccd161b08ca24 2023-12-06
FileHash-SHA256 e35cc9dd6898a857dcc7cd1b496a81cfca16696069bdf22b52f72a56d462d546 2023-12-06
FileHash-SHA256 0be4050e6282c997a7bda11b1f72930d7eda9443ac715e521a893f0c52f3e78e 2023-12-06
FileHash-SHA256 27c15bdb941231ef7e7d5303110d7057e60bae1c6c25be08ae9f364c11cde2ba 2023-12-06
FileHash-SHA256 917f5494ac20bf8f6fa64184d94c35f89eca86a37ecd1396e40cf92fc9e166a8 2023-12-06
FileHash-SHA256 ed477fd1d4924e28c0f774673baed375c2707dd28a9f335b59f615b3a8975351 2023-12-06
FileHash-SHA256 4da274435c6a571b52e6b1b5b359064fa7faace354a5103c8e52cef958bb1b02 2023-12-06
domain guard-safe.net 2023-12-06
domain apps-guard.com 2023-12-06
domain hsshvpn.net 2023-12-06
domain securevpnalarm.net 2023-12-06
domain securevpnhelp.net 2023-12-06
domain swissprox.eu 2023-12-06
domain securedtonnel.net 2023-12-06
domain safevpn24.net 2023-12-06
URL http://www.schweizerhof-wetzikon.ch/images/rtucrtmirumctrutbitueriumxe/ivotyimoyctorieotcmir.exe 2023-12-06
YARA c1e5ef54c6cb519f07788eae537e8225a8973a46 2023-12-06