Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-11-11 (WEDNESDAY) - ICEDID FROM MYRESUME.XLSB
- NOTES:
- - For the past several months, I've only seen ZLoader (SilentNight) from this campaign.
- - This time, the spreadsheet template has changed, and I'm seeing IcedID instead of ZLoader
- ASSOCIATED MALWARE:
- - SHA256 hash: fa4593b9b833602d9e309c40ec8becb6159a94d2acff372bc75a4b0a91fe2fb3
- - File size: 202,630 bytes
- - File name: myResume.xlsb
- - File description: Excel spreadsheet (XLSX) with macro for IcedID
- - SHA256 hash: 4d00dd3d606e59496069e836b1c4466d5a11a1a03c2207947f64e4442099657a
- - File size: 134,656 bytes
- - File location: http://205.185.113.20/files/3.dll
- - File location: C:\syuHKYt\vFPKnDV\VSMecyU.dll
- - File description: Installer DLL for IcedID
- - Run method: rundll32.exe [filename],DllRegisterServer
- - SHA256 hash: d25e3a7ed538968e9b78367cd8f8d20f8f55471a1eb27aae2774272fc8c1c1ce
- - File size: 125,952 bytes
- - File location: C:\Users\[username]\AppData\Local\Temp\~19228000.dll
- - File description: IcedID DLL created by the installer DLL
- - Run method: regsvr32.exe /s [filename]
- - SHA256 hash: 818076cbf3b8323b674d476b2862b3495cddcc13ef957f5bd9ec7f18bd436791
- - File size: 125,952 bytes
- - File location: C:\Users\[username]\AppData\Roaming\[username]\goibjitt1.dll
- - File description: IcedID persistent on the infected Windows host
- - Run method: regsvr32.exe /s [filename]
- TRAFFIC GENERATED BY MACRO TO RETRIEVE INSTALLER DLL:
- - 205.185.113[.]20 port 80 - 205.185.113[.]20 - GET /BVd1qKwd
- - 205.185.113[.]20 port 80 - 205.185.113[.]20 - GET /3.dll
- TRAFFIC TO LEGITMATE DOMAINS GENERATED BY INSTALLER DLL:
- - port 443 - help.twitter.com
- - port 443 - support.apple.com
- - port 443 - support.oracle.com
- - port 443 - www.oracle.com
- - port 443 - support.microsoft.com
- - port 443 - www.intel.com
- URL GENERATED BY INSTALLER DLL:
- - 143.110.191[.]95 port 443 - lezasopedrill[.]cyou - GET /background.png
- C2 DOMAINS USED BY ICEDID DLL:
- - 198.211.99[.]24 - port 443 - timerdisclaimer[.]pw
- - 198.211.99[.]24 - port 443 - experrementummo[.]pw
- - 198.211.99[.]24 - port 443 - nomoregigration[.]cyou
- - 198.211.99[.]24 - port 443 - compactmuslimsdeport[.]pw
- - 198.211.99[.]24 - port 443 - 12demuslims[.]top
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement