ExecuteMalware

2020-09-02 Emotet IOCs

Sep 2nd, 2020
3,428
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.96 KB | None | 0 0
  1.  
  2. CYBERCHEF RECIPE TO DECODE POWERSHELL
  3. From_Base64('A-Za-z0-9+/=',true)
  4. Decode_text('UTF-16LE (1200)')
  5. Split('*','\\n')
  6. Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
  7. Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
  8. Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
  9. Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
  10. Extract_URLs(false)
  11.  
  12. THREAT ATTRIBUTION: EMOTET
  13.  
  14. SENDERS OBSERVED
  15.  
  16. MALDOC DISTRIBUTION URLS
  17. http://atomek.eu/g4/http://FILE/9e24ckOJ03kGy0/
  18. http://benjamin-follert.de/walkenhorst/https://INC/ojEezCNhNwH/
  19. http://centrolegnoambiente.it/test/http://FILE/FFDMjocqzsSfcg/
  20. http://conny-dethloff.de/cgi-bin/http://LLC/o0EkDzcgyC1MUJD/
  21. http://danidatos.com/wp_01/http://public/koZtD3MTFWv7V113/
  22. http://daniel-bergmann.eu/cgi-bin/https://Documentation/bq4FO78Bs7yr8c/
  23. http://datawyse.net/cgi-bin/http://lm/Z38zZk7Lsh/
  24. http://denzler-net.de/ce_vcounter/http://Document/ApCqqLRnMyrvWB/
  25. http://dieterstula.de/cgi-bin/http://DOC/c4S5GlVo6M34IAbN/
  26. http://gueler-pl.de/blog/https://parts_service/ItmTBR6u9Wnqt3VPx/
  27. http://htkj.de/WordPress_01/https://esp/OiNU7fJml8RgO7bP/
  28. http://infoestudio.es/cursos/http://Pages/gWQn6NCdsIfwrtzdf/
  29. http://ivanmartinez.es/img/http://browse/Vyln3RL4p91g/
  30. http://ivii.de/cgi-bin/http://parts_service/peGa6jL0l8AmYkQA/
  31. http://jewefa.de/bearbeitet-hochzeit-gross/http://IpzbzJXQ0f4gZ/
  32. http://joba-mikasch.de/Engel-Dateien/http://eTrac/z4cIykmpL6QOLKKMy/
  33. http://jss-elektronik.de/lora/http://sites/brJPEX2K0kuusp3G/
  34. http://juergens-gebaeudeservice.de/cgi-bin/http://OCT/rnZjFZAKfiSoGGbz8/
  35. http://julegaveregn.dk/wp-admin/http://FILE/tJdkmCy7t7wIMk3sxch/
  36. http://jung-inet.de/cgi-bin/http://117352951704/Ebazh5T2KFyPtniV/
  37. http://justanotherrichkid.de/bilder/http://Overview/2jkW4DvghX/
  38. http://karnival.es/coutot/https://Reporting/nqWc6ClaIeDvuBJVn8/
  39. http://karsten2000.de/daten/http://DOC/S0RQXGFZXfqlj/
  40. http://kbiinformatica.com.br/wU/http://Scan/6TCHQoF2O1TcF/
  41. http://kedenburg.de/cgi-bin/https://public/j4E1pYUpOR1fYwGHbNtu/
  42. http://klaschusnet.de/cgi-bin/http://sites/0xsjoP1018/
  43. http://klein-stephan.de/cgi-bin/http://sites/UgkXWPxjA0y/
  44. http://klotzprint.de/cgi-bin/https://browse/F4NglvCvcJNxBrYxpb/
  45. http://kraus-world.com/cgi-bin/https://Scan/XCAYn3HTTlOhg8/
  46. http://labers.de/linus/http://Reporting/bmLL3xVXEIFOEb4yy8m/
  47. http://lapit.de/cgi-bin/https://lm/C5Xdyduia218/
  48. http://lapit.de/cgi-bin/https:/lm/C5Xdyduia218/
  49. http://m-kayser.de/DTCam/http://LLC/zQZ5KPFPZC/
  50. http://marcus-kuehl.de/cgi-bin/https://browse/vh3tQA572BVQgOjcoq/
  51. http://mariaseeds.es/wp-admin/https://FILE/VyJHvxduY5VEX/
  52. http://mazzolas.ch/www.mazzolas.ch/http://OCT/9cAc3oxX99jTLMh1uqka/
  53. http://minerva-bg.net/tutorials/http://lm/pRqWSkDIvzW/
  54. http://mmanke.de/cgi-bin/https://lm/XUSXJZn4KXPr6UYVQLEs/
  55. http://mtk-leuchten.de/bilder/http://FILE/7NFaogDXWvx/
  56. http://osberatung.de/cgi-bin/http://esp/HM7r90NdRX3oWK/
  57. http://ozols.de/cgi-bin/https://DOC/XXfaoVfpvcjPfg/
  58. http://pdftechnik.de/bilder/https://Overview/P0jSmSEw89dIZAuIEu/
  59. http://pielagodelmoro.es/captcha/https://esp/WD22my7lsdZrm/
  60. http://pinkesocken.de/css/https://RPBYJISIYN/Db9NbEzGTptYDtDBB0kK/
  61. http://pourcel.eu/cgi-bin/https://public/kOHD9xbHSHVwyIHu/
  62. http://qualitysale.de/cgi-bin/http://OCT/gQWoTboPyX1kRTeqi/
  63. http://rdbrd.de/assets/https://LLC/T9f7LbkEhym/
  64. http://rdbrd.de/assets/https:/LLC/T9f7LbkEhym/
  65. http://rechtsanwalt-storek.de/cgi-bin/http://Documentation/gKPYlDqI8y/
  66. http://reifendienst-bender.de/Startseite/http://mTvNGgqdZ2CBKyVMGP/
  67. http://reiten-in-stuttgart.de/cgi-bin/https://lm/W1C61q68YQG/
  68. http://reprodesign-lobbe.de/_notes/https://OCT/YrIsgJyBQu/
  69. http://reprodesign-lobbe.de/_notes/https:/OCT/YrIsgJyBQu/
  70. http://rmc-schnecken.de/_private/http://Pages/oDDDuYxGyoFxePjT6v/
  71. http://s-b-b.de/buehnenscout/https://attachments/5SGoMEVarp9XICTcpp/
  72. http://s-b-b.de/buehnenscout/https:/attachments/5SGoMEVarp9XICTcpp/
  73. http://sayn-net.de/MAF/http://sites/3kpJWvqdsIZfhv/
  74. http://schmidt-lev.de/HIT_Hunde/https://browse/M7lmH9zO7KKPLB1SQUXx/
  75. http://schockverlag.de/cgi-bin/https://attachments/39RXF3io1EN6YndK/
  76. http://schockverlag.de/cgi-bin/https:/attachments/39RXF3io1EN6YndK/
  77. http://seeger-fahrzeugtechnik.de/ce_photo/http://Document/Q4aCWlXLZK3Q6epxpmFo/
  78. http://showrent.es/Showrent/https://docs/Ete0VZ4CmtXIFjjY7c/
  79. http://siamimplement.co.th/download/http://docs/emN0lTNuYvvmz/
  80. http://slugger.de/cgi-bin/https://INC/5RBnbwVIvevkQXg0/
  81. http://socylmediapc.es/tools/https://Pages/UsrKpla3nV/
  82. http://stadtkapelle-gaildorf.de/Bilder/http://INC/7oZYOI2imMaQgXo/
  83. http://team-stark.de/cgi-bin/https://Scan/Od2iMqYVLThNyd/
  84. http://tecnicadigital.es/cgi-bin/http://234586536483/5tBR4GnvkYsY/
  85. http://tobias-erles.de/joomla_02/https://OCT/jV850cSu5KT6k/
  86. http://tomreif.de/cgi-bin/http://DOC/9wfhPTWtmVjWXzEFw6G/
  87. http://tuintrein.nl/cgi-bin/http://sites/AchNjBflu6r/
  88. http://ugira.lt/cli/http://docs/LLTiiyXpavh69XwN/
  89. http://ugira.lt/cli/http:/docs/LLTiiyXpavh69XwN/
  90. http://ulrichjohn.de/Rammstein/http://DOC/D9MVqIteLUA0HkGD/
  91. http://ultrawhite.nl/wp-includes/https://Overview/c7QWqzzekUQNLeSjLq1/
  92. http://umeoka.co.jp/js/http://Scan/GE2y8QMiRe4WwNfkC9U/
  93. http://wi-ne.de/cgi-bin/https://Documentation/L7KjTTT2wk2zg1ldLjqd/
  94. http://wiebisa.de/cgi-bin/http://DOC/M24Thm8NFJA/
  95. http://woitl.de/cgi-bin/https://Overview/i4LejrfHLZK/
  96. https://chrisjatiplus.com/wp-content/uploads/2020/08/FB6260125790SF.doc
  97. https://dziambor.net/[old]ufo361-vvs-promo/https://browse/y1olkqFHpWgJ2/
  98. https://gutachter-kanzlei.de/wp-admin/http://public/PswTL1ZoiH16dCh47Q/
  99. https://jpid.nl/data/https://sites/jl0fm5LmCXaJ3zxZ2/
  100. https://kinesiolog.de/admin/http://Pages/ZCSMJdBrlrmDNHHWi92S/
  101. https://krieger-family.de/alex42/https://lm/qH8NT1T7js4c/
  102. https://nwfinanz.de/m/http://Documentation/aaWHOK4slhw/
  103. https://obazda.de/WebCalendar_01/https://LLC/WV755sTkod/
  104. https://tpw.es/wp-includes/http://INC/ldUriluUxtY6TbCI0Ac/
  105. https://vogt-nrw.de/admin/http://YRP26Y8TKB3W2/VqfN3Yg0onEPmaf5H3/
  106. https://wandelknooppunt.nl/cgi-bin/https://docs/nGYmJwssQl/
  107. https://yoga-ein-lebensweg.de/cgi-bin/https://eTrac/A9GX8FUcM8ELyoCS/
  108.  
  109. atomek.eu
  110. benjamin-follert.de
  111. centrolegnoambiente.it
  112. chrisjatiplus.com
  113. conny-dethloff.de
  114. danidatos.com
  115. daniel-bergmann.eu
  116. datawyse.net
  117. denzler-net.de
  118. dieterstula.de
  119. dziambor.net
  120. gueler-pl.de
  121. gutachter-kanzlei.de
  122. htkj.de
  123. infoestudio.es
  124. ivanmartinez.es
  125. ivii.de
  126. jewefa.de
  127. joba-mikasch.de
  128. jpid.nl
  129. jss-elektronik.de
  130. juergens-gebaeudeservice.de
  131. julegaveregn.dk
  132. jung-inet.de
  133. justanotherrichkid.de
  134. karnival.es
  135. karsten2000.de
  136. kbiinformatica.com.br
  137. kedenburg.de
  138. kinesiolog.de
  139. klaschusnet.de
  140. klein-stephan.de
  141. klotzprint.de
  142. kraus-world.com
  143. krieger-family.de
  144. labers.de
  145. lapit.de
  146. m-kayser.de
  147. marcus-kuehl.de
  148. mariaseeds.es
  149. mazzolas.ch
  150. minerva-bg.net
  151. mmanke.de
  152. mtk-leuchten.de
  153. nwfinanz.de
  154. obazda.de
  155. osberatung.de
  156. ozols.de
  157. pdftechnik.de
  158. pielagodelmoro.es
  159. pinkesocken.de
  160. pourcel.eu
  161. qualitysale.de
  162. rdbrd.de
  163. rechtsanwalt-storek.de
  164. reifendienst-bender.de
  165. reiten-in-stuttgart.de
  166. reprodesign-lobbe.de
  167. rmc-schnecken.de
  168. s-b-b.de
  169. sayn-net.de
  170. schmidt-lev.de
  171. schockverlag.de
  172. seeger-fahrzeugtechnik.de
  173. showrent.es
  174. siamimplement.co.th
  175. slugger.de
  176. socylmediapc.es
  177. stadtkapelle-gaildorf.de
  178. team-stark.de
  179. tecnicadigital.es
  180. tobias-erles.de
  181. tomreif.de
  182. tpw.es
  183. tuintrein.nl
  184. ugira.lt
  185. ulrichjohn.de
  186. ultrawhite.nl
  187. umeoka.co.jp
  188. vogt-nrw.de
  189. wandelknooppunt.nl
  190. wi-ne.de
  191. wiebisa.de
  192. woitl.de
  193. yoga-ein-lebensweg.de
  194.  
  195. DOCUMENT FILE HASHES
  196. 337f367cf129b577295ed30e93fce0ae
  197. 90b1d02dc5056ce59a4676ee822e9fb6
  198. bf41c627046a70a5809edb9d6c2e6e5e
  199. d09ad9f2fdd568ad5e9a1994741ec74c
  200.  
  201. PAYLOAD FILE HASHES
  202. 03b1b9c059c319495f7818cb47d9569c
  203. 2cb5d4a19aa5438ed5240d663c348070
  204. 38e4cbe701b1779cc8cc1a63a2ee4f4a
  205. 3dc5feab87689f99d555606a5993a3d6
  206. 5219c85e93248e5c1995bac14ef95e4b
  207. 52b589d01a9a64444b6d1657dcc135fb
  208. 548fac349881d59544f7a023bc982fa0
  209. 63fafb0c7d8144b32a684043bc15a268
  210. 743ab81757a3971246ec4eacd671e0e5
  211. 7c2da5e6a35a9580e279aec11eadddf5
  212. 9336f2824c9f63a145d11b7f0a050901
  213. a5bf704c2494b983964ecc18e84521ea
  214. a899debf87e215e0deaeafc53ff30d1e
  215. c0f9a3127a22238e9b5a65b9d11b8bb3
  216. c41978c2f759bc1e6480e6fb02a37ac5
  217. c97a0c293dfab2f02190dcd652b7635a
  218. dc786276f9317c91c73e32b1ddf37716
  219. f3febb5bea5a5da4d1d15e4c422e39fe
  220. f5ea64a9d5c83c8c486f33036a17fd78
  221.  
  222. EMOTET PAYLOAD URLs
  223. http://easyclipping.com/cgi-bin/Ym/
  224. http://edenthedoors.com/wp-includes/nN/
  225. http://elsolivers.com/tpv/DXo/
  226. http://eltrafalgar.com/wp-includes/uYK/
  227. http://entrenofutbol.com/C2/
  228. http://evilnerd.org/cgi-bin/nUi/
  229. http://fcf.net/wentzville/maK/
  230. http://fortcollinsathletefactory.com/wp-admin/i/
  231. http://frankfurtelfarolillo.com/laseu/c7/
  232. http://gaffa-music.com/cgi-bin/UM/
  233. http://gapesmm.org/old/M/
  234. http://getming.com/forum/p/
  235. http://gnadl.net/cgi-bin/cD/
  236. http://goldschmiedemeister.net/bilder/9/
  237. http://grabner-online.org/Bibelkonverter/GCH/
  238. http://graficon.es/SOPORTE/PFY2b1s5v35546172/
  239. http://greiser.net/Ebay/m/
  240. http://grml.net/wp/C/
  241. http://hoepfner-thoma.de/Resources/file/POyhgRg/
  242. http://hubrich-hannover.de/Filme/file/CzHV/
  243. http://lektorat-rauthe.de/cgi-bin/oiwqqIFJcs/
  244. http://lember.de/cgi-bin/file/jOQmgRrKjAYB/
  245. http://malini-design.de/cgi-bin/xtRegzHUptd/
  246. http://mamakumpir.de/bilder/file/UbubmSFOLBYF/
  247. http://mmoehring.de/alt-strato/ENQnQbMFcyz/
  248. http://mmxiv.org/wp-snapshots/hwC/
  249. http://musiversum.com/cgi-bin/attach/wJmPmWFZRU/
  250. http://mym-buch.de/Alt/attach/iSd/
  251. http://neotechnology.info/cgi-bin/C6wBSadg9e0313/
  252. http://niokolo.com/0-Accueil_ALBUMS/ua/
  253. http://schlink.net/file/file/AYcTpgPvKrjnc/
  254. http://wernergansbergen.de/cgi-bin/file/dnxsUNfow/
  255. http://www.luxurygt.com/wordpress/a73/
  256. https://hopfenziz.de/bilder/attach/HsiZAvCRQwBx/
  257. https://www.flexoarquitectura.com/wp-includes/Iu/
  258.  
  259. easyclipping.com
  260. edenthedoors.com
  261. elsolivers.com
  262. eltrafalgar.com
  263. entrenofutbol.com
  264. evilnerd.org
  265. fcf.net
  266. flexoarquitectura.com
  267. fortcollinsathletefactory.com
  268. frankfurtelfarolillo.com
  269. gaffa-music.com
  270. gapesmm.org
  271. getming.com
  272. gnadl.net
  273. goldschmiedemeister.net
  274. grabner-online.org
  275. graficon.es
  276. greiser.net
  277. grml.net
  278. hoepfner-thoma.de
  279. hopfenziz.de
  280. hubrich-hannover.de
  281. lektorat-rauthe.de
  282. lember.de
  283. luxurygt.com
  284. malini-design.de
  285. mamakumpir.de
  286. mmoehring.de
  287. mmxiv.org
  288. musiversum.com
  289. mym-buch.de
  290. neotechnology.info
  291. niokolo.com
  292. schlink.net
  293. wernergansbergen.de
  294.  
  295. EMOTET C2s
  296. http://50.121.220.50
  297. http://51.75.33.122
  298. http://54.37.42.48:8080
  299. http://91.121.54.71:8080
  300. http://45.16.226.117:443
  301. http://68.69.155.181
  302. http://213.60.96.117
  303. http://77.55.211.77:8080
  304. http://152.169.22.67
  305. http://110.142.219.51
  306. http://2.47.112.152
  307. http://206.15.68.237:443
  308. http://217.13.106.14:8080
  309. http://191.99.160.58
  310. http://189.131.57.131
  311. http://213.197.182.158:8080
  312. http://94.176.234.118:443
  313. http://61.92.159.208:8080
  314. http://190.128.173.10
  315. http://219.92.8.17:8080
  316. http://190.115.18.139:8080
  317. http://190.147.137.153:443
  318. http://5.196.35.138:7080
  319. http://190.163.31.26
  320. http://70.32.115.157:8080
  321. http://114.109.179.60
  322. http://58.171.153.81
  323. http://174.100.27.229
  324. http://104.131.103.37:8080
  325. http://68.183.190.199:8080
  326. http://181.30.61.163:443
  327. http://184.66.18.83
  328. http://87.106.46.107:8080
  329. http://82.76.111.249:443
  330. http://192.241.146.84:8080
  331. http://73.213.208.163
  332. http://104.131.41.185:8080
  333. http://181.129.96.162:8080
  334. http://82.196.15.205:8080
  335. http://186.70.127.199:8090
  336. http://68.183.170.114:8080
  337. http://111.67.12.221:8080
  338. http://172.104.169.32:8080
  339. http://219.92.13.25
  340. http://45.33.77.42:8080
  341. http://185.94.252.12
  342. http://46.28.111.142:7080
  343. http://51.255.165.160:8080
  344. http://45.173.88.33
  345. http://190.24.243.186
  346. http://45.161.242.102
  347. http://77.238.212.227
  348. http://177.72.13.80
  349. http://65.36.62.20
  350. http://190.2.31.172
  351. http://212.71.237.140:8080
  352. http://64.201.88.132
  353. http://91.219.169.180
  354. http://212.174.55.22:443
  355. http://95.9.180.128
  356. http://72.135.200.124
  357. http://178.250.54.208:8080
  358. http://187.162.248.237
  359. http://178.79.163.131:8080
  360. http://77.90.136.129:8080
  361. http://70.32.84.74:8080
  362. http://98.13.75.196
  363. http://190.6.193.152:8080
  364. http://192.241.143.52:8080
  365. http://83.169.21.32:7080
  366. http://138.97.60.141:7080
  367. http://137.74.106.111:7080
  368. http://209.236.123.42:8080
  369. http://199.203.62.165
  370. http://51.159.23.217:443
  371. http://50.28.51.143:8080
  372. http://24.135.1.177
  373. http://177.73.0.98:443
  374. http://188.2.217.94
  375. http://170.81.48.2
  376. http://186.103.141.250:443
  377. http://188.135.15.49
  378. http://185.94.252.27:443
  379. http://72.47.248.48:7080
  380. http://177.74.228.34
  381. http://216.10.40.16
  382. http://103.106.236.83:8080
  383. http://217.199.160.224:7080
  384. http://190.190.148.27:8080
  385. http://12.162.84.2:8080
  386. http://85.109.159.61:443
  387. http://85.105.140.135:443
  388. http://204.225.249.100:7080
  389. http://67.247.242.247
  390. http://191.182.6.118
  391. http://189.2.177.210:443
  392. http://178.148.55.236:8080
  393. http://72.167.223.217:8080
  394. http://71.197.211.156
  395. http://190.195.129.227:8090
  396.  
  397. http://118.110.236.121:8080
  398. http://149.202.5.139:443
  399. http://153.92.4.96:8080
  400. http://51.75.163.68:7080
  401. http://105.209.235.113:8080
  402. http://77.74.78.80:443
  403. http://51.38.201.19:7080
  404. http://71.57.180.213
  405. http://139.59.12.63:8080
  406. http://185.86.148.68:443
  407. http://179.62.238.49
  408. http://58.27.215.3:8080
  409. http://81.214.253.80:443
  410. http://46.32.229.152:8080
  411. http://197.221.158.162
  412. http://81.17.93.134
  413. http://118.101.24.148
  414. http://86.98.143.163
  415. http://46.105.131.68:8080
  416. http://24.26.151.3
  417. http://41.185.29.128:8080
  418. http://54.38.143.245:8080
  419. http://220.254.198.228:443
  420. http://210.1.219.238
  421. http://185.208.226.142:8080
  422. http://91.75.75.46
  423. http://157.7.164.178:8081
  424. http://181.137.229.1
  425. http://190.212.140.6
  426. http://190.225.150.234
  427. http://103.80.51.61:8080
  428. http://190.53.144.120
  429. http://177.144.130.105:443
  430. http://101.50.232.218
  431. http://162.144.42.60:8080
  432. http://172.105.78.244:8080
  433. http://185.142.236.163:443
  434. http://45.182.161.17
  435. http://8.4.9.137:8080
  436. http://179.5.118.12
  437. http://190.55.186.229
  438. http://5.79.70.250:8080
  439. http://88.249.181.198:443
  440. http://73.84.105.76
  441. http://198.57.203.63:8080
  442. http://143.95.101.72:8080
  443. http://190.190.15.20
  444. http://2.144.244.204:443
  445. http://190.164.75.175
  446. http://189.39.32.161
  447. http://115.78.11.155
  448. http://186.227.146.102
  449. http://192.210.217.94:8080
  450. http://157.245.138.101:7080
  451. http://60.125.114.64:443
  452. http://179.191.239.255
  453. http://37.205.9.252:7080
  454. http://181.122.154.240
  455. http://50.116.78.109:8080
  456. http://91.83.93.103:443
  457. http://82.239.200.118
  458. http://113.161.148.81
  459. http://192.163.221.191:8080
  460. http://173.94.215.84
  461. http://181.113.229.139:443
  462. http://201.235.10.215
  463. http://162.249.220.190
  464. http://175.29.183.2
  465. http://190.136.179.102
  466. http://75.127.14.170:8080
  467. http://115.79.195.246
  468. http://188.0.135.237
  469. http://223.17.215.76
  470. http://74.208.173.91:8080
  471. http://192.241.220.183:8080
  472. http://37.187.100.220:7080
  473. http://66.61.94.36
  474. http://172.96.190.154:8080
  475. http://95.216.205.155:8080
  476. http://177.94.227.143
  477. http://222.159.240.58
  478. http://188.251.213.180:443
  479. http://37.46.129.215:8080
  480. http://190.96.15.50
  481. http://203.153.216.178:7080
  482. http://195.201.56.70:8080
  483. http://113.203.250.121:443
  484. http://197.232.36.108
  485. http://178.33.167.120:8080
  486. http://175.139.144.229:8080
  487. http://168.0.97.6
  488. http://201.213.177.139
  489.  
Add Comment
Please, Sign In to add comment