Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Main object- "Outstanding-Invoices"
- url http://saba.tokyo/bvylA-EemK_LhXrOC-TsM/invoices/8975/11756/US/Outstanding-Invoices/
- sha256 d4646db49726d6f3a6bc761315b54619d03ed5765822056f6cf892bd48c71c42
- sha1 0efb83d1d99206610945a97addd73a26c512daa1
- md5 8727a4ebbe11c76bac93bb9b108c2a04
- Dropped executable file
- sha256 C:\Users\admin\AppData\Local\Temp\26.exe 2cb530dd3b77e074ba3d6aad8c1076145a8b11f3b6b0d898897e404e4b00d4a1
- sha256 C:\Users\admin\AppData\Local\Temp\26.exe 649523f60460be3e494c2ad25e5dad767ee8e0f6c578fffd0f5019fb852474b5
- DNS requests
- domain techtiqdemo.co.uk
- domain pop3.lacuisine2maman.fr
- Connections
- ip 103.86.176.160
- ip 191.98.77.181
- ip 62.210.206.75
- ip 187.207.136.122
- ip 189.190.83.34
- ip 187.240.45.54
- ip 201.183.239.117
- HTTP/HTTPS requests
- url http://techtiqdemo.co.uk/3o37iwk1Qyiu_h9
- url http://techtiqdemo.co.uk/cgi-sys/suspendedpage.cgi
- url http://pop3.lacuisine2maman.fr/wp-content/aiowps_backups/8DHD4NKpNc
- url http://pop3.lacuisine2maman.fr/wp-content/aiowps_backups/8DHD4NKpNc/
- url http://201.183.239.117:8080/
- url http://187.240.45.54:443/
- url http://189.190.83.34:7080/
- HTTP requests wrote in MalDoc Macro
- http://techtiqdemo.co.uk/3o37iwk1Qyiu_h9
- http://pop3.lacuisine2maman.fr/wp-content/aiowps_backups/8DHD4NKpNc
- http://fitonutrient.com/CDMpn80Jm
- http://saspi.es/P2AWKd98r1SPrQ_NV0
- http://ftp.spbv.org/7WC0nCTOsds_9M
- Emotet C2 communication analysed with Cape Sandbox
- Couldn't analysis above sample(26.exe) with Cape Sandbox.
- So I downloaded samples from above URLs by hand then analysed with Cape Sabdbox.
- SHA256:1101a25bea3bac3704ad870ea8371b804eb474b573e3f16cedc2aee5a9e4bbb5
- 191.98.77.181:22
- 187.207.136.122:990
- 201.183.239.117:8080
- 187.240.45.54:443
- 189.190.83.34:7080
- 201.137.4.91:993
- 85.105.145.205:21
- 189.234.6.229:20
- 181.129.16.82:53
- 148.101.130.84:21
- 153.121.36.202:7080
- 137.74.173.19:8080
- 189.232.16.132:990
- 187.152.81.36:21
- 111.93.37.6:143
- 69.198.17.7:8080
- 115.71.233.127:443
- 2.50.28.190:20
- 189.141.224.222:993
- 67.223.128.207:80
- 178.254.31.162:8080
- 211.115.111.19:443
- 75.99.13.124:7080
- 94.73.197.123:20
- 91.74.62.86:8090
- 187.144.192.126:20
- 173.255.196.209:8080
- 83.222.124.62:8080
- 98.142.208.27:443
- 105.247.123.133:8080
- 217.13.106.160:7080
- 152.231.88.114:7080
- 2.50.148.99:7080
- 200.68.61.242:143
- 181.119.30.26:53
- 83.110.100.150:995
- 190.213.249.250:80
- 2.50.57.180:443
- 67.205.149.117:443
- 152.170.155.182:20
- 197.44.171.13:995
- 114.143.192.242:443
- 179.159.20.70:80
- 95.141.175.240:443
- 45.123.3.54:443
- 212.25.55.70:20
- 94.76.200.114:8080
- 45.63.17.206:8080
- 2.50.148.99:8443
- 83.110.100.150:443
- 5.230.147.179:8080
- 62.75.191.231:8080
- 189.237.108.33:465
- 198.74.58.47:443
- 69.195.223.154:7080
- 50.31.0.160:8080
- 2.50.144.32:8443
- 208.78.100.202:8080
- 66.130.129.10:8090
- 178.62.37.188:443
- References
- https://app.any.run/tasks/5389cf11-5414-4b82-8520-cff3d7b48da7
- https://cape.contextis.com/analysis/33314/
- https://cape.contextis.com/analysis/33316/
- https://www.virustotal.com/#/file/1101a25bea3bac3704ad870ea8371b804eb474b573e3f16cedc2aee5a9e4bbb5/detection
- -----------------------------------------------------------------------------------------------------------------------
- Main object- "Past-Due-Invoice"
- url http://d-trump.jp/fAMB-2714_Pawh-Nk/47410/SurveyQuestionsEn/Past-Due-Invoice/
- sha256 7126c93ba17a954d00a325c0a94da0eca53765d9382c2b42757c97cb41303456
- sha1 7951dd551cbe0d6789f003350b6eff5d977eb4d7
- md5 83508f2c6b3d4ff85f65bc3de53c6a49
- Dropped executable file
- sha256 C:\Users\admin\AppData\Local\Temp\97.exe 649523f60460be3e494c2ad25e5dad767ee8e0f6c578fffd0f5019fb852474b5
- Connections
- ip 206.189.186.211
- ip 191.98.77.181
- ip 187.207.136.122
- ip 189.190.83.34
- ip 201.183.239.117
- ip 187.240.45.54
- HTTP/HTTPS requests
- url http://salonrocket.com/IcaqhnsKoJZY_s7
- url http://salonrocket.com/IcaqhnsKoJZY_s7/
- url http://187.240.45.54:443/
- url http://201.183.239.117:8080/
- url http://189.190.83.34:7080/
- HTTP requests wrote in MalDoc Macro
- http://salonrocket.com/IcaqhnsKoJZY_s7
- http://promotion.likedoors.ru/PzpedI3jNoMQ
- http://maradop.com/QnTWqNr8vjf3fl1
- http://maxtraidingru.437.com1.ru/P9QvsI6oUtS5mCI5
- http://eczanedekorasyon.gen.tr/GTIseSRXZtnP4egB_0j6M
- Emotet C2 communication analysed with Cape Sandbox
- 191.98.77.181:22
- 187.207.136.122:990
- 201.183.239.117:8080
- 187.240.45.54:443
- 189.190.83.34:7080
- 201.137.4.91:993
- 85.105.145.205:21
- 189.234.6.229:20
- 181.129.16.82:53
- 148.101.130.84:21
- 153.121.36.202:7080
- 137.74.173.19:8080
- 189.232.16.132:990
- 187.152.81.36:21
- 111.93.37.6:143
- 69.198.17.7:8080
- 115.71.233.127:443
- 2.50.28.190:20
- 189.141.224.222:993
- 67.223.128.207:80
- 178.254.31.162:8080
- 211.115.111.19:443
- 75.99.13.124:7080
- 94.73.197.123:20
- 91.74.62.86:8090
- 187.144.192.126:20
- 173.255.196.209:8080
- 83.222.124.62:8080
- 98.142.208.27:443
- 105.247.123.133:8080
- 217.13.106.160:7080
- 152.231.88.114:7080
- 2.50.148.99:7080
- 200.68.61.242:143
- 181.119.30.26:53
- 83.110.100.150:995
- 190.213.249.250:80
- 2.50.57.180:443
- 67.205.149.117:443
- 152.170.155.182:20
- 197.44.171.13:995
- 114.143.192.242:443
- 179.159.20.70:80
- 95.141.175.240:443
- 45.123.3.54:443
- 212.25.55.70:20
- 94.76.200.114:8080
- 45.63.17.206:8080
- 2.50.148.99:8443
- 83.110.100.150:443
- 5.230.147.179:8080
- 62.75.191.231:8080
- 189.237.108.33:465
- 198.74.58.47:443
- 69.195.223.154:7080
- 50.31.0.160:8080
- 2.50.144.32:8443
- 208.78.100.202:8080
- 66.130.129.10:8090
- 178.62.37.188:443
- References
- https://app.any.run/tasks/a169d41a-a9a7-43e8-aede-592df0b59d9d
- https://cape.contextis.com/analysis/33311/
Advertisement
Add Comment
Please, Sign In to add comment