Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #remcos #RAT #stego #pngbase64 #PowerShell #RegAsm
- https://pastebin.com/
- previous_contact:
- 02/09/24 https://pastebin.com/j1ZGJxxU
- 22/08/24 https://pastebin.com/VmpVnz6b
- 16/08/24 https://pastebin.com/AkHsxz6R
- 13/08/24 https://pastebin.com/VDVp6hSi
- 19/01/24 https://pastebin.com/EvXHfZUB
- 18/01/24 https://pastebin.com/FL2fX362
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
- attack_vector
- --------------
- email attach .rar > .vbs > wscript > powershell > get bitbucket .jpg & .txt > RegAsm.exe > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Fri, 6 Sep 2024 12:37:06 +0200
- From: Господарський суд Одеської області <tsato @scl _kyoto-u _ac _jp>
- Subject: Господарський суд Одеської області -позовна заява
- Reply-To: Господарський суд Одеської області <inbox @od _arbitr _gov _ua>
- Received: from icrsun _kuicr _kyoto-u _ac _jp (HELO pfdsunb _scl _genome _ad _jp) ([133 _3 _5 _20])
- Received: from wms _scl _genome _ad _jp (wms _scl _genome _ad _jp [133 _103 _200 _205])
- Received: from gmail _com (unknown [94 _228 _169 _30])
- Message-Id: < 20240906104509 _A1F353003F065 @wms _scl _genome _ad _jp >
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 84dab25530ba75d9610b9b7e7f8665ba066679cb1e433d7657f9b0577e37717d
- File name scan_documet_027839.rar
- File size 6.78 KB (6938 bytes)
- SHA-256 cb6c92921e3bc58250684d6bd5dda9b92d22917f2d5e7b137c9694907309e986
- File name scan_documet_027839.vbs
- File size 14.46 KB (14810 bytes)
- SHA-256 700a9a6eb11bbae7ef16e727c44913861a12510c5a4b8450ce6c33f616cf1df5
- File name img_test.jpg
- File size 757.03 KB (775197 bytes)
- SHA-256 02be347bd34ba0a7ad2c5e50d1f74e88e0222eaa96ae3255c2eaa7e162c48d88
- File name img_test_2.jpg
- File size 2.46 MB (2578503 bytes)
- SHA-256 03fc22f699ba6ce9fa37f68c96fc35b6b6f8bdc7c55944977653fe2de6e1adad
- File name one.txt
- File size 683.92 KB (700332 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR bitbucket .org/ sharedua/ ua/ downloads/ scan_documet_027839.rar [decoy]
- bitbucket .org/ shieldadas/ gsdghjj/ downloads/ img_test.jpg?1181173 [loader]
- raw .githubusercontent .com/ santomalo/ audit/ main/ img_test.jpg?14441723 [loader]
- bitbucket .org/ sdgw/ sdge/ downloads/ one.txt [payload]
- C2 111_ 90 _147 _146
- netwrk
- --------------
- 185_166 _143 _48 bitbucket .org 443 TLSv1.2 Client Hello
- 54 _231 _138 _113 bbuseruploads .s3 .amazonaws .com 443 TLSv1.2 Client Hello
- 111_ 90 _147 _146 2404 TCP 50770 → 2404 [SYN]
- 178 _237 _33 _50 geoplugin .net 80 HTTP GET /json .gp HTTP/1.1
- comp
- --------------
- powershell.exe 185_166 _143 _48
- powershell.exe 54 _231 _138 _113
- RegAsm.exe 111_ 90 _147 _146
- RegAsm.exe 178 _237 _33 _50
- proc
- --------------
- "C:\Windows\System32\WScript.exe" "C:\Users\User01\Desktop\scan_documet_027839.vbs"
- "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "$codigo = . . .
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\User01\AppData\Local\Temp\qowqdmaqzvnnqivjzuponmbakptr"
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\User01\AppData\Local\Temp\aijaeelrnefaswrnieciqrwrtdlsoqh"
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\User01\AppData\Local\Temp\aijaeelrnefaswrnieciqrwrtdlsoqh"
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\User01\AppData\Local\Temp\dkot"
- "C:\Windows\System32\WScript.exe" "C:\Users\User01\AppData\Local\Temp\kvrhhlvbnsrhcjapt.vbs"
- persist
- --------------
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Fri Sep 6 15:43:28 2024
- My Program Windows PowerShell (Verified) Microsoft Windows C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exe Mon Dec 4 08:21:56 2023
- powershell.exe Invoke-Expression 'C:\Users\User01\AppData\Local\Temp\svchost.vbs'
- drop
- --------------
- %temp%\svchost.vbs
- %temp%\kvrhhlvbnsrhcjapt.vbs
- C:\ProgramData\remcos\logs.dat
- # # # # # # # #
- additional info
- # # # # # # # #
- botnet one_host
- mutex hdeshtrhj-38D4FR
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/84dab25530ba75d9610b9b7e7f8665ba066679cb1e433d7657f9b0577e37717d/details
- https://www.virustotal.com/gui/file/cb6c92921e3bc58250684d6bd5dda9b92d22917f2d5e7b137c9694907309e986/details
- https://www.virustotal.com/gui/file/700a9a6eb11bbae7ef16e727c44913861a12510c5a4b8450ce6c33f616cf1df5/details
- https://www.virustotal.com/gui/file/02be347bd34ba0a7ad2c5e50d1f74e88e0222eaa96ae3255c2eaa7e162c48d88/details
- https://www.virustotal.com/gui/file/03fc22f699ba6ce9fa37f68c96fc35b6b6f8bdc7c55944977653fe2de6e1adad/details
- VR
Add Comment
Please, Sign In to add comment