VRad

#smokeloader_201119

Nov 20th, 2019
843
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.23 KB | None | 0 0
  1. #IOC #OptiData #VR #smokeloader #LZH #SCR #UPX
  2.  
  3. ID by help of @James_inthe_box
  4.  
  5. https://pastebin.com/BJzcXqkK
  6.  
  7. previous_contact:
  8. https://pastebin.com/kBW7nkZ5
  9. https://pastebin.com/Z7zq0YkW
  10. https://pastebin.com/b8PkhMyN
  11. https://pastebin.com/hkskwKvc
  12. https://pastebin.com/JmthzrL4
  13. https://pastebin.com/1scwT0f8
  14. https://pastebin.com/MP3kCSSh
  15.  
  16. FAQ:
  17. https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
  18. https://research.checkpoint.com/2019-resurgence-of-smokeloader/
  19.  
  20. attack_vector
  21. --------------
  22. email attach .RAR > .LZH > SCR > explorer > taskeng > regsvr32 > Roaming\buhtujv
  23.  
  24. email_headers
  25. --------------
  26. Date: Wed, 20 Nov 2019 05:03:08 +0200
  27. Return-Path: <[email protected]>
  28. Received: from mx-out-2.default-host.net (mx-out-2.default-host.net [185.234.176.21])
  29. Received: from [127.0.0.1] (unknown [81.22.255.150]) by mx-out-2.default-host.net (Postfix) with ESMTPA id 08B9E12196B
  30. Subject: Re: Задолжность за листопад
  31. X-Mailer: iPhone Mail (13E238)
  32. X-FEAS-CLIENT-IP: 185.234.176.21
  33.  
  34. files
  35. --------------
  36. SHA-256 cbe03fcaab00a2fa69a06ccfe4b9798c922a081befc4d6494b8b625290c458c1
  37. File name рах.ф. до оплати за листопад за договором № 18-А.rar [RAR archive data, v8, os: OS/2 ]
  38. File size 282.66 KB (289446 bytes)
  39.  
  40. SHA-256 a95b23f00132f69eb562fb84bb88e75ce019105936daa1c82a4be6a464b56c96
  41. File name рахунки до оплати за листопад.lzh [LHa (2.x)/LHark archive data [lh7] - header level 0 ]
  42. File size 255.78 KB (261923 bytes)
  43.  
  44. SHA-256 9198dd9af0b3cd11ebe90d0e44e2d582688e6eeb62780b9f0bb40312cd9da49c
  45. File name file.scr [UPX, PE32 executable for MS Windows (GUI) Intel 80386 32-bit]
  46. File size 291.5 KB (298496 bytes)
  47.  
  48. SHA-256 b0adf16a99c3259fd571fbd22595cb4f8aae6fac347fd4e4eb1bae25eb3f0d6c
  49. File name file_unpack.scr [PE32 executable for MS Windows (GUI) Intel 80386 32-bit ]
  50. File size 380.5 KB (389632 bytes)
  51.  
  52. SHA-256 8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c
  53. File name ntdll.dll [PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit ]
  54. File size 1.23 MB (1292192 bytes)
  55.  
  56. activity
  57. **************
  58. PL_SCR attachment
  59.  
  60. C2 manikurshoping{.}ru 194.15.36.70
  61.  
  62. netwrk
  63. --------------
  64. 194.15.36.70 manikurshoping.ru POST / HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
  65.  
  66. comp
  67. --------------
  68. explorer.exe 194.15.36.70
  69.  
  70. proc
  71. --------------
  72. C:\Users\operator\Desktop\decoy.scr /S
  73. C:\Windows\SysWOW64\explorer.exe
  74. C:\Windows\system32\taskeng.exe {ID} S-1-5-21-...:APM11\operator:Interactive:LUA[1]
  75. C:\Windows\system32\regsvr32.EXE /s /n /u /i:"C:\Users\admin\AppData\Roaming\jugfabc" scrobj
  76. C:\Users\operator\AppData\Roaming\buhtujv
  77.  
  78. persist
  79. --------------
  80. n/a
  81.  
  82. drop
  83. --------------
  84. %temp%\****.tmp [ntdll.dll]
  85. operator\AppData\Roaming\buhtujv
  86.  
  87. # # #
  88. https://www.virustotal.com/gui/file/cbe03fcaab00a2fa69a06ccfe4b9798c922a081befc4d6494b8b625290c458c1/details
  89. https://www.virustotal.com/gui/file/a95b23f00132f69eb562fb84bb88e75ce019105936daa1c82a4be6a464b56c96/details
  90.  
  91. >UPX
  92. https://www.virustotal.com/gui/file/9198dd9af0b3cd11ebe90d0e44e2d582688e6eeb62780b9f0bb40312cd9da49c/details
  93. https://analyze.intezer.com/#/analyses/3871328f-1f63-4346-84a9-576c3361b561
  94.  
  95. >unpacked
  96. https://www.virustotal.com/gui/file/b0adf16a99c3259fd571fbd22595cb4f8aae6fac347fd4e4eb1bae25eb3f0d6c/details
  97. https://analyze.intezer.com/#/analyses/42fea4fa-aea6-4737-b826-d8adbb49b01e
  98.  
  99. >dll
  100. https://www.virustotal.com/gui/file/8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c/details
  101. https://analyze.intezer.com/#/analyses/b69fe4fb-3966-449e-a86b-e2eb4f529481
  102.  
  103. @ @ @
  104. meta
  105. --------------
  106. File Name : рах.ф. до оплати за листопад за договором № 18-А.rar
  107. Directory : .
  108. File Size : 283 kB
  109. File Modification Date/Time : 2019:11:20 10:52:00+02:00
  110. File Access Date/Time : 2019:11:20 11:14:49+02:00
  111. File Inode Change Date/Time : 2019:11:20 11:14:34+02:00
  112. File Permissions : rw-rw-rw-
  113. Error : File format error
  114.  
  115.  
  116. File Name : рахунки до оплати за листопад.lzh
  117. Directory : .
  118. File Size : 256 kB
  119. File Modification Date/Time : 2019:11:20 03:03:36+02:00
  120. File Access Date/Time : 2019:11:20 10:53:26+02:00
  121. File Inode Change Date/Time : 2019:11:20 10:53:03+02:00
  122. File Permissions : rw-rw-r--
  123. Error : Unknown file type
  124.  
  125.  
  126. File Name : decoy_upx.scr
  127. File Size : 292 kB
  128. File Modification Date/Time : 2019:11:20 02:11:22+02:00
  129. File Access Date/Time : 2019:11:20 11:05:27+02:00
  130. File Inode Change Date/Time : 2019:11:20 11:05:27+02:00
  131. File Permissions : rw-------
  132. File Type : Win32 EXE
  133. File Type Extension : exe
  134. MIME Type : application/octet-stream
  135. Machine Type : Intel 386 or later, and compatibles
  136. Time Stamp : 2019:11:20 02:11:19+02:00
  137. PE Type : PE32
  138. Language Code : English (U.S.)
  139. Character Set : Unicode
  140. Legal Copyright : Copyright ©OVH. 1999 - 2014
  141. Original File Name : ParasitesSenders.exe
  142. File Description : Spending Cres Rdn Cascading
  143. Company Name : OVH
  144. Languages : English
  145. Product Name : ParasitesSenders
  146. Product Version : 3.8.6.2
  147.  
  148.  
  149. File Name : decoy_unpack.exe
  150. File Size : 380 kB
  151. File Modification Date/Time : 2019:11:20 02:11:22+02:00
  152. File Access Date/Time : 2019:11:20 11:35:53+02:00
  153. File Inode Change Date/Time : 2019:11:20 11:35:50+02:00
  154. File Permissions : rw-------
  155. File Type : Win32 EXE
  156. File Type Extension : exe
  157. MIME Type : application/octet-stream
  158. Machine Type : Intel 386 or later, and compatibles
  159. Time Stamp : 2019:11:20 02:11:19+02:00
  160. PE Type : PE32
  161. Language Code : English (U.S.)
  162. Character Set : Unicode
  163. Legal Copyright : Copyright ©OVH. 1999 - 2014
  164. Original File Name : ParasitesSenders.exe
  165. File Description : Spending Cres Rdn Cascading
  166. Company Name : OVH
  167. Languages : English
  168. Product Name : ParasitesSenders
  169. Product Version : 3.8.6.2
  170.  
  171.  
  172. ExifTool Version Number : 10.10
  173. File Name : table_clean.xls
  174. File Size : 42 kB
  175. File Modification Date/Time : 2019:11:19 02:47:30+02:00
  176. File Access Date/Time : 2019:11:20 11:14:34+02:00
  177. File Inode Change Date/Time : 2019:11:20 11:04:30+02:00
  178. File Permissions : rw-------
  179. File Type : XLS
  180. File Type Extension : xls
  181. MIME Type : application/vnd.ms-excel
  182. Author : VIP9
  183. Last Modified By : RePack by Diakov
  184. Software : Microsoft Excel
  185. Last Printed : 2018:02:20 08:54:41
  186. Create Date : 2016:11:20 11:19:57
  187. Modify Date : 2019:11:19 00:47:28
  188. Security : None
  189. Code Page : Windows Cyrillic
  190. Company : Grizli777
  191. App Version : 14.0000
  192. Scale Crop : No
  193. Links Up To Date : No
  194. Shared Doc : No
  195. Hyperlinks Changed : No
  196. Title Of Parts : остатки кукуруза, остатки соя, 'остатки кукуруза'!Область_печати
  197. Heading Pairs : Листы, 2, Именованные диапазоны, 1
  198.  
  199.  
  200. File Name : Яковлева копия для договора.jpg
  201. Directory : .
  202. File Size : 27 kB
  203. File Modification Date/Time : 2018:03:13 09:15:56+02:00
  204. File Access Date/Time : 2019:11:20 10:53:20+02:00
  205. File Inode Change Date/Time : 2019:11:20 10:53:03+02:00
  206. File Permissions : rw-rw-r--
  207. File Type : JPEG
  208. File Type Extension : jpg
  209. MIME Type : image/jpeg
  210. JFIF Version : 1.01
  211. Exif Byte Order : Big-endian (Motorola, MM)
  212. X Resolution : 37.795
  213. Y Resolution : 37.795
  214. Resolution Unit : cm
  215. Software : paint.net 4.0.4
  216. Image Width : 800
  217. Image Height : 559
  218. Encoding Process : Baseline DCT, Huffman coding
  219. Bits Per Sample : 8
  220. Color Components : 3
  221. Y Cb Cr Sub Sampling : YCbCr4:2:0 (2 2)
  222. Image Size : 800x559
  223. Megapixels : 0.447
  224.  
  225.  
  226.  
  227. VR
Advertisement
Add Comment
Please, Sign In to add comment