Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #smokeloader #LZH #SCR #UPX
- ID by help of @James_inthe_box
- https://pastebin.com/BJzcXqkK
- previous_contact:
- https://pastebin.com/kBW7nkZ5
- https://pastebin.com/Z7zq0YkW
- https://pastebin.com/b8PkhMyN
- https://pastebin.com/hkskwKvc
- https://pastebin.com/JmthzrL4
- https://pastebin.com/1scwT0f8
- https://pastebin.com/MP3kCSSh
- FAQ:
- https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
- https://research.checkpoint.com/2019-resurgence-of-smokeloader/
- attack_vector
- --------------
- email attach .RAR > .LZH > SCR > explorer > taskeng > regsvr32 > Roaming\buhtujv
- email_headers
- --------------
- Date: Wed, 20 Nov 2019 05:03:08 +0200
- Reply-To: alfredpinol@meta.ua
- Return-Path: <s.netluh@airport.lviv.ua>
- Received: from mx-out-2.default-host.net (mx-out-2.default-host.net [185.234.176.21])
- Received: from [127.0.0.1] (unknown [81.22.255.150]) by mx-out-2.default-host.net (Postfix) with ESMTPA id 08B9E12196B
- From: s.netluh@airport.lviv.ua
- Subject: Re: Задолжность за листопад
- X-Mailer: iPhone Mail (13E238)
- X-FEAS-CLIENT-IP: 185.234.176.21
- files
- --------------
- SHA-256 cbe03fcaab00a2fa69a06ccfe4b9798c922a081befc4d6494b8b625290c458c1
- File name рах.ф. до оплати за листопад за договором № 18-А.rar [RAR archive data, v8, os: OS/2 ]
- File size 282.66 KB (289446 bytes)
- SHA-256 a95b23f00132f69eb562fb84bb88e75ce019105936daa1c82a4be6a464b56c96
- File name рахунки до оплати за листопад.lzh [LHa (2.x)/LHark archive data [lh7] - header level 0 ]
- File size 255.78 KB (261923 bytes)
- SHA-256 9198dd9af0b3cd11ebe90d0e44e2d582688e6eeb62780b9f0bb40312cd9da49c
- File name file.scr [UPX, PE32 executable for MS Windows (GUI) Intel 80386 32-bit]
- File size 291.5 KB (298496 bytes)
- SHA-256 b0adf16a99c3259fd571fbd22595cb4f8aae6fac347fd4e4eb1bae25eb3f0d6c
- File name file_unpack.scr [PE32 executable for MS Windows (GUI) Intel 80386 32-bit ]
- File size 380.5 KB (389632 bytes)
- SHA-256 8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c
- File name ntdll.dll [PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit ]
- File size 1.23 MB (1292192 bytes)
- activity
- **************
- PL_SCR attachment
- C2 manikurshoping{.}ru 194.15.36.70
- netwrk
- --------------
- 194.15.36.70 manikurshoping.ru POST / HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
- comp
- --------------
- explorer.exe 194.15.36.70
- proc
- --------------
- C:\Users\operator\Desktop\decoy.scr /S
- C:\Windows\SysWOW64\explorer.exe
- C:\Windows\system32\taskeng.exe {ID} S-1-5-21-...:APM11\operator:Interactive:LUA[1]
- C:\Windows\system32\regsvr32.EXE /s /n /u /i:"C:\Users\admin\AppData\Roaming\jugfabc" scrobj
- C:\Users\operator\AppData\Roaming\buhtujv
- persist
- --------------
- n/a
- drop
- --------------
- %temp%\****.tmp [ntdll.dll]
- operator\AppData\Roaming\buhtujv
- # # #
- https://www.virustotal.com/gui/file/cbe03fcaab00a2fa69a06ccfe4b9798c922a081befc4d6494b8b625290c458c1/details
- https://www.virustotal.com/gui/file/a95b23f00132f69eb562fb84bb88e75ce019105936daa1c82a4be6a464b56c96/details
- >UPX
- https://www.virustotal.com/gui/file/9198dd9af0b3cd11ebe90d0e44e2d582688e6eeb62780b9f0bb40312cd9da49c/details
- https://analyze.intezer.com/#/analyses/3871328f-1f63-4346-84a9-576c3361b561
- >unpacked
- https://www.virustotal.com/gui/file/b0adf16a99c3259fd571fbd22595cb4f8aae6fac347fd4e4eb1bae25eb3f0d6c/details
- https://analyze.intezer.com/#/analyses/42fea4fa-aea6-4737-b826-d8adbb49b01e
- >dll
- https://www.virustotal.com/gui/file/8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c/details
- https://analyze.intezer.com/#/analyses/b69fe4fb-3966-449e-a86b-e2eb4f529481
- @ @ @
- meta
- --------------
- File Name : рах.ф. до оплати за листопад за договором № 18-А.rar
- Directory : .
- File Size : 283 kB
- File Modification Date/Time : 2019:11:20 10:52:00+02:00
- File Access Date/Time : 2019:11:20 11:14:49+02:00
- File Inode Change Date/Time : 2019:11:20 11:14:34+02:00
- File Permissions : rw-rw-rw-
- Error : File format error
- File Name : рахунки до оплати за листопад.lzh
- Directory : .
- File Size : 256 kB
- File Modification Date/Time : 2019:11:20 03:03:36+02:00
- File Access Date/Time : 2019:11:20 10:53:26+02:00
- File Inode Change Date/Time : 2019:11:20 10:53:03+02:00
- File Permissions : rw-rw-r--
- Error : Unknown file type
- File Name : decoy_upx.scr
- File Size : 292 kB
- File Modification Date/Time : 2019:11:20 02:11:22+02:00
- File Access Date/Time : 2019:11:20 11:05:27+02:00
- File Inode Change Date/Time : 2019:11:20 11:05:27+02:00
- File Permissions : rw-------
- File Type : Win32 EXE
- File Type Extension : exe
- MIME Type : application/octet-stream
- Machine Type : Intel 386 or later, and compatibles
- Time Stamp : 2019:11:20 02:11:19+02:00
- PE Type : PE32
- Language Code : English (U.S.)
- Character Set : Unicode
- Legal Copyright : Copyright ©OVH. 1999 - 2014
- Original File Name : ParasitesSenders.exe
- File Description : Spending Cres Rdn Cascading
- Company Name : OVH
- Languages : English
- Product Name : ParasitesSenders
- Product Version : 3.8.6.2
- File Name : decoy_unpack.exe
- File Size : 380 kB
- File Modification Date/Time : 2019:11:20 02:11:22+02:00
- File Access Date/Time : 2019:11:20 11:35:53+02:00
- File Inode Change Date/Time : 2019:11:20 11:35:50+02:00
- File Permissions : rw-------
- File Type : Win32 EXE
- File Type Extension : exe
- MIME Type : application/octet-stream
- Machine Type : Intel 386 or later, and compatibles
- Time Stamp : 2019:11:20 02:11:19+02:00
- PE Type : PE32
- Language Code : English (U.S.)
- Character Set : Unicode
- Legal Copyright : Copyright ©OVH. 1999 - 2014
- Original File Name : ParasitesSenders.exe
- File Description : Spending Cres Rdn Cascading
- Company Name : OVH
- Languages : English
- Product Name : ParasitesSenders
- Product Version : 3.8.6.2
- ExifTool Version Number : 10.10
- File Name : table_clean.xls
- File Size : 42 kB
- File Modification Date/Time : 2019:11:19 02:47:30+02:00
- File Access Date/Time : 2019:11:20 11:14:34+02:00
- File Inode Change Date/Time : 2019:11:20 11:04:30+02:00
- File Permissions : rw-------
- File Type : XLS
- File Type Extension : xls
- MIME Type : application/vnd.ms-excel
- Author : VIP9
- Last Modified By : RePack by Diakov
- Software : Microsoft Excel
- Last Printed : 2018:02:20 08:54:41
- Create Date : 2016:11:20 11:19:57
- Modify Date : 2019:11:19 00:47:28
- Security : None
- Code Page : Windows Cyrillic
- Company : Grizli777
- App Version : 14.0000
- Scale Crop : No
- Links Up To Date : No
- Shared Doc : No
- Hyperlinks Changed : No
- Title Of Parts : остатки кукуруза, остатки соя, 'остатки кукуруза'!Область_печати
- Heading Pairs : Листы, 2, Именованные диапазоны, 1
- File Name : Яковлева копия для договора.jpg
- Directory : .
- File Size : 27 kB
- File Modification Date/Time : 2018:03:13 09:15:56+02:00
- File Access Date/Time : 2019:11:20 10:53:20+02:00
- File Inode Change Date/Time : 2019:11:20 10:53:03+02:00
- File Permissions : rw-rw-r--
- File Type : JPEG
- File Type Extension : jpg
- MIME Type : image/jpeg
- JFIF Version : 1.01
- Exif Byte Order : Big-endian (Motorola, MM)
- X Resolution : 37.795
- Y Resolution : 37.795
- Resolution Unit : cm
- Software : paint.net 4.0.4
- Image Width : 800
- Image Height : 559
- Encoding Process : Baseline DCT, Huffman coding
- Bits Per Sample : 8
- Color Components : 3
- Y Cb Cr Sub Sampling : YCbCr4:2:0 (2 2)
- Image Size : 800x559
- Megapixels : 0.447
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement