Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #Lumma #Stealer #AutoIT #PWD
- https://pastebin.com/5P3sDqtv
- previous_contact:
- 12/02/24 https://pastebin.com/uRwsPe70
- 31/01/24 https://pastebin.com/0sqGs6aV
- 30/01/24 https://pastebin.com/pgjwR07Z
- 27/01/24 https://pastebin.com/4B3hwvpx
- 25/01/24 https://pastebin.com/pwL5HdeX
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma
- attack_vector
- --------------
- email URL > bitbucket > GET .7z > .rar (PWD) > .exe > .pif > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Wed, 14 Feb 2024 14:32:30 +0300
- Subject: Запит № 8128430 від: 14.02.2024
- From: Носковська Ія Жданівна <obaidulkarim@ salvochemical_com>
- Reply-To: Іллєнко Яртур Іванович <info@ svenscholten_com>
- Received: from server2422_quanticdynamics_cloud ([103_209_40_166])
- Received: from [5_42_92_31] (port=53970 helo= DESKTOP - TCRDU4C)
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 9ab215973dfae21dcf34a17846953985db5340305470b4d0e39077d31de2510b
- File name Doc.7z
- SHA-256 2bfab0128280dc8e548f0bfb7e8ea35e28b20939b649df8c673a1cab2c9c8c45
- File name Рахунок на оплату – досудова претензія Medoc.rar
- SHA-256 baeced1519471f5b87271beb193b279983078f0bba9ba4daef9af842b3c361b8
- File name Рахунок на оплату – досудова претензія Medoc.xls.exe
- SHA-256 a12adcef2a153e0926843befaad18c7378d8d1b698400c51a69b229f99979d54
- File name MedicationRoy.exe
- SHA-256 f58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3
- File name Biography.pif , Supporting.pif , Be.pif
- SHA-256 412ea561f1fddaab3c4a0543031a61b63e762461e32554e2927e6fc0212ac6cb
- File name vns.exe
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR bitbucket_org /obmens/file/downloads/ Doc.7z
- C2 .site , .fun , .store
- netwrk
- --------------
- n/a
- comp
- --------------
- n/a
- proc
- --------------
- C:\Users\USER_NAME\Desktop\files1402\Рахунок на оплату – досудова претензія Medoc.xls.exe
- "C:\Windows\System32\cmd.exe" /k move Nfl Nfl.bat & Nfl.bat & exit
- C:\Windows\SysWOW64\tasklist.exe
- C:\Windows\SysWOW64\findstr.exe /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe"
- C:\Windows\SysWOW64\tasklist.exe
- C:\Windows\SysWOW64\findstr /I "wrsa.exe opssvc.exe"
- C:\Windows\SysWOW64\cmd.exe /c md 30936
- C:\Windows\SysWOW64\cmd.exe /c copy /b Membership + Unsubscribe + Toilet + Counties + September 30936\Biography.pif
- C:\Windows\SysWOW64\cmd.exe /c copy /b Howard + Modem + Hostel 30936\A
- C:\TEMP\7ZipSfx.000\30936\Biography.pif 30936\A
- C:\Windows\SysWOW64\PING.EXE -n 5 localhost
- persist
- --------------
- n/a
- drop
- --------------
- %temp%\7ZipSfx.000\30936\Biography.pif
- %temp%\7ZipSfx.000\30936\A
- # # # # # # # #
- additional info
- # # # # # # # #
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/9ab215973dfae21dcf34a17846953985db5340305470b4d0e39077d31de2510b/details
- https://www.virustotal.com/gui/file/2bfab0128280dc8e548f0bfb7e8ea35e28b20939b649df8c673a1cab2c9c8c45/details
- https://www.virustotal.com/gui/file/baeced1519471f5b87271beb193b279983078f0bba9ba4daef9af842b3c361b8/details
- https://www.virustotal.com/gui/file/a12adcef2a153e0926843befaad18c7378d8d1b698400c51a69b229f99979d54/details
- https://www.virustotal.com/gui/file/f58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3/details
- https://www.virustotal.com/gui/file/412ea561f1fddaab3c4a0543031a61b63e762461e32554e2927e6fc0212ac6cb/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement