Advertisement
VRad

#azorult_170918

Sep 17th, 2018
822
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.77 KB | None | 0 0
  1. #IOC #OptiData #VR #170918 #azorult #RTF #118882
  2.  
  3. SHA-256 3cf7272c35aad460bd3c162e4e1499c383ac06dec02ef36e506eb50d9e84116f
  4. File name QUOTATION N0AB.doc
  5. File size 444.09 KB
  6. Last analysis 2018-09-17 11:17:10 UTC
  7.  
  8. SHA-256 6767b6974e104025cac4ace55ca70580b8d838415900be85b6c193efc79921a4
  9. File name PO.jpg (EXE)
  10. File size 316 KB
  11.  
  12. network
  13. --------------
  14. 67.199.248.10 bit.ly GET /2NhNeOU HTTP/1.1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64;
  15. 192.198.87.130 vitani.tk GET /PO.jpg HTTP/1.1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64;
  16. 185.193.38.78 cashouts.tk POST /index.php HTTP/1.1 Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)
  17. 185.193.38.78 cashouts.tk POST /index.php HTTP/1.1 Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)
  18.  
  19. openconnect
  20. --------------
  21. EQNEDT32.EXE 3376 TCP 67.199.248.11 80 ESTABLISHED
  22. EQNEDT32.EXE 3376 TCP 192.198.87.130 80 ESTABLISHED
  23.  
  24. proc
  25. --------------
  26. "C:\Program Files (x86)\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
  27. "C:\Users\operator\AppData\Roaming\test.exe"
  28. C:\Windows\System32\cmd.exe" /c copy "C:\Users\operator\AppData\Roaming\test.exe" "C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\office.exe"
  29. "C:\Windows\System32\explorer.exe" /c, "C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\office.exe"
  30.  
  31. persist
  32. --------------
  33. office.exe Diagnose SQL Server performance issues Syenergy Consulting & Representation Ltd c:\users\operator\appdata\roaming\microsoft\windows\start menu\programs\startup\office.exe 15.04.1992 16:05
  34. office.lnk Diagnose SQL Server performance issues Syenergy Consulting & Representation Ltd c:\users\operator\appdata\roaming\microsoft\windows\start menu\programs\startup\office.exe 15.04.1992 16:05
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement