Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #PureCrypter #ZGRat #PureLog #Stealer #MassLogger #RAR #EXE
- https://pastebin.com/CaYPSqnB
- previous_contact:
- 18/08/20 https://pastebin.com/4uXgesYV
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.purecrypter
- https://malpedia.caad.fkie.fraunhofer.de/details/win.masslogger
- attack_vector
- --------------
- email attach .gz (RAR) > .exe > get .dat > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: 29 Jan 2024 03:15:03 +0100
- Subject: ref_swift_a2390e
- From: Madalin Ceausescu <madalin@infosuyunrnedical_com>
- Received: from mail.infosuyunrnedical_com ([104_168_173_98])
- Received: from [172_93_160_112] (unknown [172_93_160_112])
- Message-ID: <20240129031503.2B85E10C1C4D420D@infosuyunrnedical_com>
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 4a639abd12bfb6f6d66d9d3dd3ec4034f34e05dd91d0c5e9f9ae99ce0b97cf51
- File name CopyofSwift_41AUD_....gz [RAR archive data, v5]
- File size 69.85 KB (71527 bytes)
- SHA-256 3522c4380138f81dce5085c66b158b6069238c6737ece7be4b433c29fcfcc39b
- File name CopyofSwift.exe [Microsoft Visual C++ vx.x DLL] !PureCrypter
- File size 198.16 KB (202912 bytes)
- SHA-256 79bba6492afd8013bf0e6c2671215f0710abb72a63796a4eb817ec0afa04cf56
- File name Raliycrvk.dat [data, HomeLab/BraiLab Tape image] !MassLogger
- File size 1.35 MB (1418752 bytes)
- SHA-256 5f0e72e1839db4aa41f560e0a68c7a95c9e1656bc2f4f4ff64803655d02e5272
- File name sqlite.interop.dll [Win32 DLL] !SQLite3
- File size 1.75 MB (1830064 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR sata-alloy_com / puzzle / Raliycrvk.dat
- C2 94_156_66_79 : 6734
- netwrk
- --------------
- 162_0_211_204 sata-alloy_com 80 HTTP GET / puzzle / Raliycrvk.dat HTTP/1.1
- 94_156_66_79 6734 TCP 49242 → 6734 [SYN]
- comp
- --------------
- CopyofSwift.exe 2664 TCP 162_0_211_204 80 ESTABLISHED
- CopyofSwift.exe 2664 TCP 94_156_66_79 6734 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\CopyofSwift.exe
- C:\Users\operator\Desktop\CopyofSwift.exe
- persist
- --------------
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 29.01.2024 10:25
- TRichViewDelphi.vbs
- c:\users\operator\appdata\roaming\microsoft\windows\start menu\programs\startup\trichviewdelphi.vbs
- drop
- --------------
- C:\Users\operator\AppData\Roaming\TRichViewDelphi.exe
- %temp%Fzvibvnol.tmp
- %temp%Mwhmpjhm.tmp
- %temp%Costura\1485B29524EF63EB83DF771D39CCA767\64\sqlite.interop.dll
- %temp%Crziehgh\axdea46y.default\logins.json
- %temp%Crziehgh\axdea46y.default\key3.db
- # # # # # # # #
- additional info
- # # # # # # # #
- exe description: TRichView VCL Trial for Delphi Setup
- company: Sergei Vladimirovich Tkachenko IP
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/4a639abd12bfb6f6d66d9d3dd3ec4034f34e05dd91d0c5e9f9ae99ce0b97cf51/details
- https://www.virustotal.com/gui/file/3522c4380138f81dce5085c66b158b6069238c6737ece7be4b433c29fcfcc39b/details
- https://analyze.intezer.com/analyses/328c90c4-1a33-4f21-93e7-ce2e772e5fc5
- https://www.virustotal.com/gui/file/79bba6492afd8013bf0e6c2671215f0710abb72a63796a4eb817ec0afa04cf56/details
- https://www.virustotal.com/gui/file/5f0e72e1839db4aa41f560e0a68c7a95c9e1656bc2f4f4ff64803655d02e5272/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement