ExecuteMalware

2020-09-08 Emotet IOCs

Sep 8th, 2020
3,489
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.00 KB | None | 0 0
  1. CYBERCHEF RECIPE TO DECODE POWERSHELL SCRIPT
  2. From_Base64('A-Za-z0-9+/=',true)
  3. Decode_text('UTF-16LE (1200)')
  4. Split('*','\\n')
  5. Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
  6. Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
  7. Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
  8. Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
  9. Extract_URLs(false)
  10.  
  11.  
  12. THREAT ATTRIBUTION: EMOTET
  13. I can't say with certainty if the 2 documents that I downloaded were from today or yesterday.
  14. I suspect yesterday, however.
  15.  
  16. SUBJECTS OBSERVED
  17. None
  18.  
  19. SENDERS OBSERVED
  20. None
  21.  
  22. MALDOC DISTRIBUTION URLS
  23. http://tarravalleyfoods.com.au/awstats/http:/OCT/Dm2yEAoApkxvx/
  24. http://www.alfapress.com/form/http:/browse/mt5wzrldAEQ8GjkYxO/
  25.  
  26. WORD DOCUMENT FILE HASHES
  27. 4b2a3819f609433d4aee7caa93f2035f
  28. a6d7ed8fc2065320b5da489be82655e7
  29.  
  30. PAYLOAD FILE HASHES
  31. 693b2498489aa81a6121cb991f47bd59
  32. 9fd5e8dc6586baaeb8e8f30f9244e7fe
  33. f40a7ec4d252eb261c283d07de9181dd
  34.  
  35. EMOTET PAYLOAD URLs
  36. http://aldama.com/www/jkm/
  37. http://ebu.no/billett/VMs/
  38. http://fotoboule.de/bba/file/TyfJoGH/
  39. http://frankroller.de/cgi-bin/attach/edFGzwpekjnwk/
  40. http://franzosenbach.de/Meerbusch/igHfjN/
  41. http://gerotax.de/assets/attach/rEzDDIkWAlZ/
  42. http://gms2006.de/cgi-bin/file/fEyZ/
  43. http://maximumwebimpact.com/test/rL9/
  44. http://must-in.com/wp-admin/Q/
  45. http://sriharshampromoters.com/sriharshaptr/8/
  46. http://staniszczak.net/cpf/F/
  47. http://www.bismarjeparamebel.com/wp-includes/SX/
  48. https://gestoriasanchez.es/paginas/Vqywzqmas498299/
  49. https://twisterprint.com/stats/KsU/
  50.  
  51. EMOTET C2s
  52. http://185.215.227.107:443
  53. http://51.38.124.206
  54. http://38.88.126.202:8080
  55. http://54.37.42.48:8080
  56. http://172.104.169.32:8080
  57. http://68.183.190.199:8080
  58. http://187.162.248.237
  59. http://82.76.111.249:443
  60. http://184.66.18.83
  61. http://190.6.193.152:8080
  62. http://77.238.212.227
  63. http://199.203.62.165
  64. http://188.2.217.94
  65. http://185.94.252.12
  66. http://178.250.54.208:8080
  67. http://206.15.68.237:443
  68. http://65.36.62.20
  69. http://216.47.196.104
  70. http://219.92.8.17:8080
  71. http://213.60.96.117
  72. http://77.55.211.77:8080
  73. http://72.167.223.217:8080
  74. http://177.74.228.34
  75. http://186.103.141.250:443
  76. http://190.163.31.26
  77. http://85.109.159.61:443
  78. http://68.183.170.114:8080
  79. http://213.197.182.158:8080
  80. http://45.161.242.102
  81. http://71.197.211.156
  82. http://104.131.103.37:8080
  83. http://94.176.234.118:443
  84. http://190.2.31.172
  85. http://5.196.35.138:7080
  86. http://190.195.129.227:8090
  87. http://67.247.242.247
  88. http://64.201.88.132
  89. http://152.169.22.67
  90. http://24.135.1.177
  91. http://191.182.6.118
  92. http://51.159.23.217:443
  93. http://110.142.219.51
  94. http://68.69.155.181
  95. http://82.196.15.205:8080
  96. http://77.90.136.129:8080
  97. http://181.129.96.162:8080
  98. http://45.33.77.42:8080
  99. http://95.9.180.128
  100. http://192.241.146.84:8080
  101. http://91.219.169.180
  102. http://188.135.15.49
  103. http://212.71.237.140:8080
  104. http://98.13.75.196
  105. http://72.47.248.48:7080
  106. http://209.236.123.42:8080
  107. http://217.13.106.14:8080
  108. http://219.92.13.25
  109. http://177.72.13.80
  110. http://12.162.84.2:8080
  111. http://177.73.0.98:443
  112. http://50.121.220.50
  113. http://185.178.10.77
  114. http://216.10.40.16
  115. http://61.92.159.208:8080
  116. http://170.81.48.2
  117. http://45.16.226.117:443
  118. http://185.94.252.27:443
  119. http://217.199.160.224:7080
  120. http://178.79.163.131:8080
  121. http://186.70.127.199:8090
  122. http://91.121.54.71:8080
  123. http://190.190.148.27:8080
  124. http://190.24.243.186
  125. http://138.97.60.141:7080
  126. http://104.131.41.185:8080
  127. http://73.213.208.163
  128. http://181.30.61.163:443
  129. http://103.106.236.83:8080
  130. http://192.241.143.52:8080
  131. http://87.106.46.107:8080
  132. http://2.47.112.152
  133. http://45.173.88.33
  134. http://204.225.249.100:7080
  135. http://111.67.77.202:8080
  136. http://70.32.115.157:8080
  137. http://111.67.12.221:8080
  138. http://70.32.84.74:8080
  139. http://58.171.153.81
  140. http://190.147.137.153:443
  141. http://190.115.18.139:8080
  142. http://83.169.21.32:7080
  143. http://5.189.178.202:8080
  144. http://50.28.51.143:8080
  145. http://137.74.106.111:7080
  146. http://189.2.177.210:443
  147. http://72.135.200.124
  148. http://51.255.165.160:8080
Add Comment
Please, Sign In to add comment