Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #template_injection #generated_maldoc #possilbe_gamaredon #pirated_msoffice
- https://pastebin.com/AeXB3n7j
- previous_contact:
- 2x/08/20 https://pastebin.com/HUKPF31d
- 18/11/19 https://pastebin.com/Vhb4KF5L
- FAQ:
- https://attack.mitre.org/techniques/T1221/
- https://malpedia.caad.fkie.fraunhofer.de/actor/gamaredon_group
- https://intezer.com/blog/malware-analysis/analyze-malicious-microsoft-office-files/
- attack_vector
- --------------
- email attach .doc (template_inject.) > GET 185.247.184.} 152 > n/a
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Fri, 15 Sep 2023 09:25:34 +0300
- Received: from frv190.fwdcdn.com ([212.42.77.190])
- Received: from [10.10.80.23] (helo=frv50.fwdcdn.com) by frv190.fwdcdn.com with smtp ID 1qh2Gm-00094e-Ll
- From: Центр Державних Замовлень <cdz25@ukr.net>
- Received: from cdz25@ukr.net by frv50.fwdcdn.com;
- Subject: Для УПОВНОВАЖЕНИХ ОСІБ: 19 - 21 вересня онлайн семінар (зі змінами від 01.09.2023 № 952) Платформа ZOOM;
- Message-Id: <1694759099.0854066000.aidykooe@frv50.fwdcdn.com>
- Return-Path: cdz25@ukr.net
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 01d27b175fcc3c7917223abe51e55adbb69d052bfccc189d30df2b4cb2c35480
- File name Пропозиція для участі у семінарі 2023 рік(Онлайн).doc [ MS Word Document ]
- File size 273.00 KB (279552 bytes)
- SHA-256 f557b22f065af690fe89a2e3d27539e2f8fb27dc6c9446ac3637e7f3a082537f
- File name Анкета-заявка онлайн.doc [ MS Word Document ] - clean
- File size 47.00 KB (48128 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR http://encyclopedia83{ .samiseto{ .ru/HOME-PC/registry/sorry/amiable/amiable/amiable.83glf
- C2 n/a
- netwrk
- --------------
- 185.247.184.} 152 encyclopedia83.{ samiseto.{ ru 80 HTTP OPTIONS /HOME-PC/registry/sorry/amiable/amiable/ Microsoft Office Protocol Discovery
- 185.247.184.} 152 encyclopedia83.{ samiseto.{ ru 80 HTTP OPTIONS /HOME-PC/registry/sorry/amiable Microsoft-WebDAV-MiniRedir/6.1.7601
- 185.247.184.} 152 encyclopedia83.{ samiseto.{ ru 80 HTTP GET /HOME-PC/registry/sorry/amiable/amiable/amiable.83glf Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64)
- comp
- --------------
- WINWORD.EXE 2492 TCP 185.247.184.} 152 80 ESTABLISHED
- proc
- --------------
- "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde
- persist
- --------------
- n/a
- drop
- --------------
- n/a
- # # # # # # # #
- additional info - maldoc_metadata
- # # # # # # # #
- File Name : Пропозиція для участі у семінарі 2023 рік(Онлайн).doc
- File Size : 280 kB
- File Modification Date/Time : 2023:09:15 12:07:00+03:00
- File Access Date/Time : 2023:09:15 12:08:10+03:00
- File Inode Change Date/Time : 2023:09:15 12:07:43+03:00
- File Type : DOC
- MIME Type : application/msword
- Identification : Word 8.0
- Language Code : Russian
- Author : User
- Template : amiable.83glf
- Last Modified By : User
- Software : Microsoft Office Word
- Create Date : 2023:09:12 07:34:00
- Modify Date : 2023:09:12 07:34:00
- Company : Reanimator Extreme Edition
- Char Count With Spaces : 3504
- App Version : 12.0000
- Hyperlinks : tel:+380987902839, tel:+380638790210
- Last Printed : 2018:08:03 11:32:00
- Revision Number : 3
- Total Edit Time : 1 minute
- Words : 524
- Characters : 2987
- Pages : 1
- Paragraphs : 7
- Lines : 24
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/01d27b175fcc3c7917223abe51e55adbb69d052bfccc189d30df2b4cb2c35480/details
- https://analyze.intezer.com/analyses/73d64402-0da6-4504-964d-3858765041e5
- https://www.virustotal.com/gui/url/5558092a781ac40c676aff5d9efab4ea6e9f0f976c9cc1733484f9530f546ce2/details
- https://www.virustotal.com/gui/file/f557b22f065af690fe89a2e3d27539e2f8fb27dc6c9446ac3637e7f3a082537f/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement