Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #rurat #RemoteUtilitiesLLC #EXE #UPX
- https://pastebin.com/70CvpLRE
- previous_contact:
- 03/03/21 https://pastebin.com/vBf6Wyr5
- 03/03/21 https://pastebin.com/br4Cayaz
- FAQ:
- https://www.remoteutilities.com/download/#
- attack_vector
- --------------
- email > attach .zip > .rar > .exe1 (UPX) > exe2 > install > service > 195.24.68.15 / 194.156.99.64
- email_headers
- --------------
- Received: from mail.mepr.gov.ua (mail.menr.gov.ua [194.183.172.242])
- Received: from gmail.com (31.13.19.242) by SERV-MAIL.menr.local (10.11.12.9)
- with Microsoft SMTP Server id 14.3.498.0; Tue, 9 Mar 2021 03:45:16 +0200
- From: Чорнуцький Сергій Петрович <[email protected]> [spoofed]
- Subject: Судовий запит № 72137269
- previous contact:
- **************
- Received: from mail.mepr.gov.ua (mail.menr.gov.ua [194.183.172.242])
- (envelope-from [email protected])
- Received: from gmail.com (176.100.167.8) by SERV-MAIL.menr.local (10.11.12.9)
- with Microsoft SMTP Server id 14.3.498.0; Wed, 3 Mar 2021 11:05:16 +0200
- From: Кравець Олександр Олександрович <[email protected]>
- Subject: Електронний запит (довіданий) Терміново!
- files
- --------------
- SHA-256 d9ae788efeaf1a9d8d9a4208e6f8f61585f9e1cd1585a4c31bd86f026b11e5e1
- File name Електронний запит.zip [Zip archive data, at least v1.0 to extract]
- File size 19.92 MB (20891981 bytes)
- SHA-256 c1481929963b670912aa4c1ac3fa03a9f90a7d2f45605344c5f31a5bb2c020e6
- File name Електронний запит.rar [RAR archive data, v9a, flags: Locked, Solid,]
- File size 19.92 MB (20891525 bytes)
- SHA-256 e7c63f751c086428cef790142154b1c2bfffecac4d9e8ad00f1fe70dd8aaf069
- File name Електронний запит.exe [PE32 executable, UPX 2.90 [LZMA]] ! Signed file, valid signature
- File size 20.41 MB (21401712 bytes)
- SHA-256 2d4ef054f2ff2d64271b34f057943cf2b0f2c21ceb32df23e86f964cc1bb1a4b
- File name unpack.exe [PE32 executable, BobSoft Mini Delphi]
- File size 22.81 MB (23913072 bytes)
- installed [the same as previous, just other config for C2]
- --------------
- SHA-256 3ac6a07500a732e7c61ebb0f67a1ac6552201d3b6a94c8b28ebfbc86119fb279
- File name host.msi [Microsoft Windows Installer] ! Signed file, valid signature
- File size 20.50 MB (21492224 bytes)
- SHA-256 85b67377703bb2b9509d2fb895bb96d2afd42fe2e69f3d6c265f3a5e5c239598
- File name rutserv.exe [PE32 executable, BobSoft Mini Delphi] ! Signed file, valid signature
- File size 17.39 MB (18236152 bytes)
- SHA-256 1f54cb5415178dcb7d43c158898aed122e443a2edd15c85f525fce9cad01ae41
- File name rfusclient.exe [ PE32 executable ] ! Signed file, valid signature
- File size 10.71 MB (11235064 bytes)
- original_utility (signed, not modified)
- --------------
- SHA-256 d4d3ef9196b5dac53d1e06d738eb3e529578752bf9e8cfd2900a600d5f10a7e5
- File name host7.0.0.1.exe [PE32 executable, UPX 2.90 [LZMA]]
- File size 20.41 MB (21397752 bytes)
- activity
- **************
- PL_SCR attached exe
- C2 195.24.68.15 [Moscow, Russian Federation]
- 194.156.99.64 [Republic of Moldova, Chisinau]
- previous contact:
- **************
- 139.28.38.254
- netwrk
- --------------
- tcp.port == 80 || tcp.port == 8080 || tcp.port == 5651
- 194.156.99.64 51208 → 8080 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- 195.24.68.15 51213 → 8080 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- !previous contact:
- **************
- tcp.port == 80 || tcp.port == 8080 || tcp.port == 5651
- tcp.port == 82 || tcp.port == 5652 || tcp.port == 465
- comp
- --------------
- rutserv.exe 3768 TCP 195.24.68.15 80 ESTABLISHED
- rutserv.exe 3768 TCP 195.24.68.15 8080 ESTABLISHED
- rutserv.exe 3768 TCP 195.24.68.15 5651 ESTABLISHED
- rutserv.exe 3768 TCP 194.156.99.64 80 ESTABLISHED
- rutserv.exe 3768 TCP 194.156.99.64 8080 ESTABLISHED
- rutserv.exe 3768 TCP 194.156.99.64 5651 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\Електронний запит.exe
- C:\Users\operator\Desktop\Електронний запит.exe
- "C:\Windows\System32\msiexec.exe" /i "C:\Users\support\AppData\Local\Temp\RUT_{49DBFD43-8B37-4CA0-8BA1-72BE6F901143}\host.msi" /qn
- {another context}
- C:\Windows\system32\msiexec.exe /V
- C:\Windows\syswow64\MsiExec.exe -Embedding 20D9D0B218A5A1E1FE855C1C00173276
- "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" -msi_copy "C:\Users\support\AppData\Local\Temp\RUT_{49DBFD43-8B37-4CA0-8BA1-72BE6F901143}\host.msi"
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /silentinstall
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /firewall
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /start
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -service
- "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe"
- "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray
- "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -firewall
- persist
- --------------
- HKLM\System\CurrentControlSet\Services 09.03.2021 17:07
- RManService Allows Remote Utilities users to connect to this machine. Remote Utilities LLC
- c:\program files (x86)\remote utilities - host\rutserv.exe 28.02.2021 14:25
- "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -service
- drop
- --------------
- C:\ProgramData\Remote Utilities\msi\70001_{CE1C66C6-55D6-4DAE-98B7-B8C7FE87342D}\host.msi
- C:\Users\support\AppData\Local\Temp\RUT_{49DBFD43-8B37-4CA0-8BA1-72BE6F901143}\host.msi
- C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe
- C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe
- C:\Program Files (x86)\Remote Utilities - Host\*
- # # #
- https://www.virustotal.com/gui/file/d9ae788efeaf1a9d8d9a4208e6f8f61585f9e1cd1585a4c31bd86f026b11e5e1/details
- https://www.virustotal.com/gui/file/c1481929963b670912aa4c1ac3fa03a9f90a7d2f45605344c5f31a5bb2c020e6/details
- https://www.virustotal.com/gui/file/e7c63f751c086428cef790142154b1c2bfffecac4d9e8ad00f1fe70dd8aaf069/details
- https://www.virustotal.com/gui/file/2d4ef054f2ff2d64271b34f057943cf2b0f2c21ceb32df23e86f964cc1bb1a4b/details
- IP
- **************
- https://www.virustotal.com/gui/ip-address/195.24.68.15/details
- https://www.virustotal.com/gui/ip-address/194.156.99.64/details
- installed
- **************
- https://www.virustotal.com/gui/file/3ac6a07500a732e7c61ebb0f67a1ac6552201d3b6a94c8b28ebfbc86119fb279/details
- https://www.virustotal.com/gui/file/85b67377703bb2b9509d2fb895bb96d2afd42fe2e69f3d6c265f3a5e5c239598/details
- https://www.virustotal.com/gui/file/1f54cb5415178dcb7d43c158898aed122e443a2edd15c85f525fce9cad01ae41/details
- original_utility
- **************
- https://www.virustotal.com/gui/file/d4d3ef9196b5dac53d1e06d738eb3e529578752bf9e8cfd2900a600d5f10a7e5/details
- VR
Add Comment
Please, Sign In to add comment