Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: EMOTET
- CYBERCHEF RECIPE TO GET URLS FROM THE BASE64-ENCODED POWERSHELL SCRIPT
- ----------------------------------------------------------------------
- From_Base64('A-Za-z0-9+/=',true)
- Decode_text('UTF-16LE (1200)')
- Split('*','\\n')
- Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'`'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'=Y3nkOs'},' ',true,false,true,false)
- Split('@','\\n')
- Find_/_Replace({'option':'Simple string','string':'J3s2'},'/',true,false,true,false)
- Extract_URLs(false)
- SENDERS OBSERVED
- aafin3@saps.com.pk
- absolutethaicic@seacuisine.com.my
- adminlae@manogeneralservices.com
- Airline03@mattressdirect.com
- antoine.bernheim@sudjuristes.fr
- Asad.ullah@ilmauniversity.edu.pk
- auxiliaribague@inacar.com
- butterflyhotel@evita-hotels.com
- calvinonggo@eseco.co.id
- careers@shafishoes.com
- carlos.gama@maispertodesi.pt
- carlos.sosa@appcore.mx
- coordinadorlogisticoregion.pacifico@gopack365.com
- doguscicekci@tekbasgrup.com
- eastwest@eastwest.ro
- edgar@kus.com.ph
- egutierrez@aytonavacerrada.org
- faturamento@bevianitransportes.com.br
- general@mecatec.hn
- glasgowsales@mfsgroup.co.zw
- h.brissaud.75120@paris.notaires.fr
- h_boram@dandace.jp
- hernane.ribeiro@aac.cv
- herry@ravindopm.com
- info@tsotrastst.gr
- ioannidisv@klidarithmos.gr
- jetro_vicente@dt-factory.com
- julie.carpanini.78111@paris.notaires.fr
- maliha@fm91.com.pk
- mohd.hamed@alhilalcapital.ae
- nadyfarahat@dhabicontracting.com
- ostoja.ivanovic@bip.co.rs
- pdv006860@simplysardegna.com
- production@nafcocoatings.com
- r.nikova@sheynovo-ag.eu
- reservation@pthotel.vn
- rj@rgmengineering.net
- sales@rgtech.tech
- sgb@butterfly-lg.com
- shamim@singwah.com
- shan@powermagicelec.com
- Social.95036@paris.notaires.fr
- spraza@siddiqsonsgroup.com
- sshaba@rcz.org.zw
- testa@amazonfoods.ae
- thomas@bpsl.net
- thuannt@shintsbvt.com
- thuy.tran@smartsurvey.com.vn
- tomovsol@mbox.contact.bg
- transportadoras@majestic.com.br
- tseptember@mpnetwork.org.za
- vanessa.barony@pignusmontagem.com
- ventas@mecatec.hn
- waseem.ansari@chase.pk
- MALDOC DISTRIBUTION URLS
- http://379code.com/rec_site/u/
- http://51.104.243.215/wp-content/1m1phEKnm7Yxx/
- http://amarteargentina.com.ar/wp-admin/1PBCSSi33FN7IPhc/
- http://annabphotography.co.uk/wp-includes/t8dI6v/
- http://avanttipisos.com.br/catalogo-virtual/i1XnbBRzXXXrqGLfBZ3UNn6Yjh1mubdZKDm48wvQD3thzthxMysX/
- http://caballo.com.au/arabians_htm_files/QshdpdaxEhJYs7jJXGQ/
- http://camminachetipassa.it/icaqf83fflrlm6d8xqfk1sgl4zq4eqtasmy1bgnvg6fmcbya89ia6iid5qwtsuhb/
- http://catchpoolshetlands.co.uk/border-design-fjk/8fGEiO7xg7WfdRWDoQ/
- http://colfarse.com.ar/colfar/ZLucvhsj5FFvq5GC5NEi0K9AUThp/
- http://cuadros.pe/personal_sector/uyol9rQZq00rUNlKzBTSr3ZXzW42WXMizFoeyPfMvWe6lNL/
- http://dentalalliance.se/wp-admin/UyTpqmldkf67M7oqYSpBDCA3VQsg9GTvTA3ulrFHRKUuCjqIpvG02kejwSt2/
- http://ff.vishou.net/static/cnhAJnGYfhUWaVjupktcfydjI8LtBmqj17ft0YVDZF4Vwi6WsysT7aBqKXf7R2k/
- http://futuregraphics.com.ar/esp/LcHx70VyC/
- http://greensync.com.br/aspnet_clientOld/Dbd6MTtmukhp0fZUYwV/
- http://hesa.co.id/_errorpages/54ioffqqt8rey6DU7GH/
- http://imaspro.com/done/page/css/RXXjEyB8JQU/
- http://imindtech.com/l/vB8p34smQK7yqGyBjMreZHcPAq0v7sgcBDolLF8J1dbeoR6FyH4YJDq6muJIVt/
- http://inaotheoyeucau.com/wp-content/Lqc4vQ22pw7un/
- http://jiafunongye.com/application/Oq39CDBoJAPl5BXx7K2iViylLLivre9K/
- http://kevinley.com/lib/Hz9FTkbmAytMwBJikJ755nYw9rzO0uNKtgca/
- http://lblcomputacion.com/services/52r6pfMGbWCoY32iWRMSrShatHkghBoNK85bduKA4PXWlCPCYwc1HbBYCG/
- http://merkadito.mx/upload/3FI5Z8BI0nwi42Q312tuQwuLqqmtRdf53EMPbKcwsItZCCR5f/
- http://mlrodasepneus.com.br/index11/NNjzVXE4iK54pJCPRZb2ZfqnCbPtE6Wyei/
- http://nirmalvermicompost.com/printsaga.in/wdAwnc6WqcdSUTrTBjPKw6SN/
- http://omilen.cl/wordpress/o5MLV1qQlaZNrKSU1SyA/
- http://randradeseguros.com.br/produtos/LHwfUihcnUZo38T15EhCTPhOB4FwZJ3QRrxx3Hr9/
- http://sasystemsuk.com/index_files/2xke/
- http://snpconsulting.com.au/Documents/S4fgk9KdJl9YnV47haL/
- http://swiftlogisticseg.com/wp-admin/PPL/
- http://syracusecoffee.com/customer/I7XXOVU4L3YVkEithMWiQ2ZnZ/
- http://vuatritue.com/wp-admin/ddCqa5l9bAEIl/
- http://www.toplevel.com.br/medico/wuEeTldQTSKCYLrggl97PUJb7x99t1/
- http://www.x-treme.gr/kritikos/3.2.Sep2019/logs/dgWE4INdW1DdrDjpuQsgy4VLXkYpL9nAZ1NpezunTJFsLg3K7P/
- https://52.221.6.170/well-known/Hqp2ZWrlUCCubgY/
- https://ajstudiollc.com/cgi-bin/azvkj9RT3ghV017Le4fm6H3V/
- https://liubaozi.cn/wordpress/wayW90OoXCT5diCZSYmJ1qg5XZyS3x86p5/
- https://nonnarina.ax/wp-content/TgjpYgCSgQJAPYCZDPrzF8XAK4f1esP0V3d7PTY/
- https://paisocial.org/wp-includes/DaiyEBsh2lt4Jwwf8lndfnL5U3Q5Jp0e3Id8nXRxs/
- https://phucdu.cf/wp-admin/iGGoSNhhMLNb3a780Qyd2c5OUmVLK/
- https://srishtiherbs.com/jms/uwLD9lewOZrnEUTvCGDXaZ7mBs/
- https://sunbayhotel.vn/wp-content/Av1CoybiHY4GqECQgoMG8a6Z0OdKaOHEBnAbmdyc7iUAZBp1I18gDNx7rfFaeHxxtPXV/
- https://teleguru.com.au/wp-content/PmzcwGED/
- https://terplandia.com/publish_f2/j57DVgxq5B3kbJ6ckaxsZG/
- https://x.ziyoubb.com.cn/wp-includes/WkcTboK3jM1MKm3EuF9pdIGREGrqyuHX/
- https://zzznan.com/wp-admin/NL9wu1TisXOy1RVpkCyGfvtoQe8r2Grvon8eggV0MNTeI7RUUBIi5ntluBkrAF/
- 379code.com
- ajstudiollc.com
- amarteargentina.com.ar
- annabphotography.co.uk
- avanttipisos.com.br
- caballo.com.au
- camminachetipassa.it
- catchpoolshetlands.co.uk
- colfarse.com.ar
- cuadros.pe
- dentalalliance.se
- futuregraphics.com.ar
- greensync.com.br
- hesa.co.id
- imaspro.com
- imindtech.com
- inaotheoyeucau.com
- jiafunongye.com
- kevinley.com
- lblcomputacion.com
- liubaozi.cn
- merkadito.mx
- mlrodasepneus.com.br
- nirmalvermicompost.com
- nonnarina.ax
- omilen.cl
- paisocial.org
- phucdu.cf
- randradeseguros.com.br
- sasystemsuk.com
- snpconsulting.com.au
- srishtiherbs.com
- sunbayhotel.vn
- swiftlogisticseg.com
- syracusecoffee.com
- teleguru.com.au
- terplandia.com
- toplevel.com.br
- vishou.net
- vuatritue.com
- x-treme.gr
- ziyoubb.com.cn
- zzznan.com
- DOCUMENT FILE HASHES
- 153643e9b1055571b289f3b456e40ff5
- 463eb7e2c29b88d3a094ccdce03caa65
- 7544fa02879a60decfafe039f8977c76
- 77f5669faf8b543a3a9b31a9e05ad65b
- 83187840bbd9923f44cbfd64e7d09679
- 90f8b0288f5257128c3d53f7b4dd0da2
- d9db3c40c53b786cb43e29301d53928a
- fc2597c20a99be987a753a84fb861d2f
- PAYLOAD FILE HASHES
- 18b23ff53477834ded58c1f99ea729d0
- 4735a3a21ba6aac9eec7017ca9481fad
- 508e8c108ac35dc73763a3ba3c081e33
- 81d13f98f4187cf2f2976be9ff36c8c9
- 8b117cf4c943500f993ab2c80ab3a1c1
- ae88e9fc6fb133e8f42d42ea3a87365f
- b774782a8b6effd1b59efd21bc80d3e2
- cf3befcefb8b7655e76804f00f8857d9
- e22ca344e5e427983f40d7caab0ea41c
- ee12cd722441b54819530ac0f4f0d698
- EMOTET PAYLOAD URLs
- http://aeropilates.cl/wp-content/Service/
- http://aramisconstruct.ro/wp-admin/uX/
- http://arquivopop.com.br/index_htm_files/Kxh/
- http://assecon.com.br/novoassecon/diagnostics/
- http://azraktours.com/wp-content/NWF9jC/
- http://biglaughs.org/smallpotatoes/rRwRzc/
- http://blog.vishou.net/admin/font/
- http://brand360.vn/bljgz/93U/
- http://cheetahridge.mediadevstaging.com/c/B/
- http://elemsindikat.com.mk/shadow-vip-2pxdt/Pyh/
- http://expeditionquest.com/X/
- http://geoffoglemusic.com/wp-admin/x/
- http://goldcoastoffice365.com/temp/X/
- http://helionspharmaceutical.com/wp-admin/oXJB/
- http://hotelshivansh.com/UserFiles/8/
- http://jarodcharity.org/wp-includes/9ocR/
- http://josegene.com/theme/gU8/
- http://koreankidsedu.com/wp-content/2cQTh/
- http://mateusz1infa.5v.pl/titan-structures-dotzt/Rl555/
- http://megasolucoesti.com/R9KDq0O8w/Microsoft.NET/
- http://ownitconsignment.com/files/b/
- http://parakkunnathtemple.com/bckup/7SDAvi/
- http://paulscomputing.com/CraigsMagicSquare/H/
- http://phasdesign.com/wordpress/MSInfo/
- http://pos-egypt.com/wp-content/xTr/
- http://preparateparaloquevenga.com/predisi-tgl-jlpml/jjvCL/
- http://resuco.net/wp-content/uploads/2020/12/S0K/
- http://riandutra.com/img/dRWJ5aN5/
- http://siamimplement.co.th/images/System32/
- http://talkischeap.co.za/4-pin-iscru/t7k/
- http://transfersuvan.com/wp-admin/OVl/
- http://vod.vishou.net/data/6hCNth/
- http://www.greaudstudio.com/docs/FGn/
- http://zhongshixingchuang.com/wp-admin/OTm/
- https://accordiblehr.com/wp-admin/HdzyEn/
- https://ardenneweb.com/765779o900/re/
- https://b2bcom.com.br/site/0H/
- https://cairocad.com/cgi-bin/1PBB/
- https://dagranitegiare.com/wp-admin/jCH/
- https://goldilockstraining.com/wp-includes/bftt/
- https://jeffdahlke.com/css/bg4n3/
- https://mobgroup.com.br/wp-content/font/
- https://mrveggy.com/erros/s0/
- https://norailya.com/vendor/1j/
- https://physio-svdh.ch/wp-admin/kK/
- https://pox23.io/wp-content/I/
- https://snjwellers.com/wp-includes/esttW/
- https://suriagrofresh.com/serevers/MVDjI/
- https://unikaryapools.com/wp/Speech/
- https://whytech.info/wp-includes/HceUxFK/
- https://www.alshuwail.com/cgi-bin/5/
- https://www.isatechnology.com/training/b/
- https://www.lavenderkart.com/blogs/nZP5c/
- https://www.lixko.com/wp-includes/VGX/
- https://www.talktalkenglish.vn/database/v/
- https://www.themoviebazar.com/2007-bmw/Help/
- https://www.wellnursesmartnurse.co.za/wp-admin/HFdox/
- accordiblehr.com
- aeropilates.cl
- alshuwail.com
- aramisconstruct.ro
- ardenneweb.com
- arquivopop.com.br
- assecon.com.br
- azraktours.com
- b2bcom.com.br
- biglaughs.org
- brand360.vn
- cairocad.com
- cheetahridge.mediadevstaging.com
- dagranitegiare.com
- elemsindikat.com.mk
- expeditionquest.com
- geoffoglemusic.com
- goldcoastoffice365.com
- goldilockstraining.com
- greaudstudio.com
- helionspharmaceutical.com
- hotelshivansh.com
- isatechnology.com
- jarodcharity.org
- jeffdahlke.com
- josegene.com
- koreankidsedu.com
- lavenderkart.com
- lixko.com
- mateusz1infa.5v.pl
- megasolucoesti.com
- mobgroup.com.br
- mrveggy.com
- norailya.com
- ownitconsignment.com
- parakkunnathtemple.com
- paulscomputing.com
- phasdesign.com
- physio-svdh.ch
- pos-egypt.com
- pox23.io
- preparateparaloquevenga.com
- resuco.net
- riandutra.com
- siamimplement.co.th
- snjwellers.com
- suriagrofresh.com
- talkischeap.co.za
- talktalkenglish.vn
- themoviebazar.com
- transfersuvan.com
- unikaryapools.com
- vishou.net
- wellnursesmartnurse.co.za
- whytech.info
- zhongshixingchuang.com
- EMOTET C2s
- http://67.170.250.203:443
- http://70.92.118.112
- http://50.116.111.59:8080
- http://173.249.20.233:443
- http://188.165.214.98:8080
- http://187.161.206.24
- http://37.139.21.175:8080
- http://24.69.65.8:8080
- http://78.24.219.147:8080
- http://87.106.139.101:8080
- http://110.145.11.73
- http://67.10.155.92
- http://152.170.205.73
- http://109.74.5.95:8080
- http://176.111.60.55:8080
- http://110.145.101.66:443
- http://190.162.215.233
- http://118.83.154.64:443
- http://217.20.166.178:7080
- http://168.235.67.138:7080
- http://185.201.9.197:8080
- http://62.75.141.82
- http://119.59.116.21:8080
- http://100.37.240.62
- http://200.116.145.225:443
- http://209.141.54.221:7080
- http://161.0.153.60
- http://72.229.97.235
- http://95.213.236.64:8080
- http://64.207.182.168:8080
- http://74.40.205.197:443
- http://79.137.83.50:443
- http://134.209.144.106:443
- http://174.118.202.24:443
- http://58.1.242.115
- http://108.21.72.56:443
- http://115.94.207.99:443
- http://190.146.92.48
- http://144.217.7.207:7080
- http://138.68.87.218:443
- http://181.165.68.127
- http://181.171.209.241:443
- http://185.94.252.104:443
- http://49.205.182.134
- http://74.208.45.104:8080
- http://50.91.114.38
- http://41.185.28.84:8080
- http://188.219.31.12
- http://123.176.25.234
- http://194.4.58.192:7080
- http://61.19.246.238:443
- http://137.59.187.107:8080
- http://74.75.104.224
- http://110.145.77.103
- http://24.178.90.49
- http://139.162.60.124:8080
- http://167.114.153.111:8080
- http://136.244.110.184:8080
- http://190.240.194.77:443
- http://62.30.7.67:443
- http://220.245.198.194
- http://190.29.166.0
- http://139.99.158.11:443
- http://94.23.237.171:443
- http://62.171.142.179:8080
- http://202.134.4.216:8080
- http://50.245.107.73:443
- http://120.150.60.189
- http://74.128.121.17
- http://172.86.188.251:8080
- http://202.141.243.254:443
- http://201.241.127.190
- http://208.74.26.234
- http://120.150.218.241:443
- http://72.188.173.74
- http://24.179.13.119
- http://46.105.131.79:8080
- http://172.125.40.123
- http://172.104.97.173:8080
- http://202.134.4.211:8080
- http://203.153.216.189:7080
- http://75.143.247.51
- http://121.124.124.40:7080
- http://157.245.99.39:8080
- http://72.186.136.247:443
- http://2.58.16.89:8080
- http://89.216.122.92
- http://142.112.10.95:20
- http://37.187.72.193:8080
- http://155.186.9.160
- http://51.89.36.180:443
- http://109.116.245.80
- http://5.39.91.110:7080
- http://139.59.60.244:8080
- http://172.105.13.66:443
- http://104.131.11.150:443
- http://85.105.111.166
- http://47.144.21.37
- http://95.9.5.93
- http://186.74.215.34
- http://5.2.212.254
Add Comment
Please, Sign In to add comment