ExecuteMalware

2020-10-01 Emotet IOCs

Oct 1st, 2020
5,678
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.33 KB | None | 0 0
  1. THREAT ATTRIBUTION: EMOTET
  2.  
  3. CYBERCHEF RECIPE TO DECODE POWERSHELL SCRIPT
  4. From_Base64('A-Za-z0-9+/=',true)
  5. Decode_text('UTF-16LE (1200)')
  6. Split('*','\\n')
  7. Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
  8. Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
  9. Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
  10. Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
  11. Extract_URLs(false)
  12.  
  13. SENDERS OBSERVED
  14.  
  15. MALDOC DISTRIBUTION URLS
  16. http://gustosoesemplice.com/m1owt/browse/xSVV1qjDSNdBB60qJMNv/
  17. https://gncnacionaldeconsultores.com/wp-admin/docs/gJvCmGFHW46/
  18. https://www.erfa.web.tr/wp-admin/parts_service/PMI0MTmVu4I/
  19. https://hian.vn/wp-content/uploads/elementor/FGMZR3A8IQ6UK1/4fe5VO9t7viTQQBYc5O/
  20. http://infoquick.co.uk/business_card/browse/xXUc1CrZr378je64W65/
  21. http://ganeshkulariya.com/wp-includes/SFIZNsASdtrsroTw7o/
  22. http://jegsnet.com/wp-content/browse/MXLm4RagesLCAcKap6f/
  23. http://rezvankosar.ir/dpqbUXK3el/jMk8jBlFFmx/
  24. http://zabor-pro.store/bfn/Reporting/mu3sHgNkdLAKvynPSWP/
  25. http://www.sifesro.com/wp-includes/0EM6NXHC9OXU4B/NkMmTWIVsbYkyF2Ilc3I/
  26. http://qutiche.cn/wp-admin/Document/edxJZZaYURAGsWWWP/
  27. https://hao.fengxiaopeng.cn/wp-includes/VPRZSX0F5PE/sFAS1JsUPoLc7TwZDge/
  28. http://amberadvisors.com.hk/wp-admin/browse/2179pirozapdgyqu/
  29. http://hianstore.com/wp-content/swift/13eul7/
  30. http://thietkenoithatthongminh.org/wp-content/statement/
  31. http://vanphongmau.com/swift/ree11m4o21hfjjxk55/
  32. http://enetra.in/wp-content/DOC/9pixkh/
  33. http://metube.world/wp-admin/report/
  34. http://profblogging.com/wp-admin/esp/
  35. http://360wifi.com.cn/wp-admin/css/parts_service/
  36. http://pailingroup.net/wp-admin/8iwwnxts6wtq9twp75kpv/
  37. http://partohesab.ir/www/paclm/g682w/
  38. https://pixelwalkerrproduction.com/model/sites/
  39. http://siyahkalemresim.com/yedek/invoice/kpz9b3ruixkp/uaaoutps/
  40. http://mail.jogjatraveling.com/Drupa/eTrac/
  41. http://scaierp.com/wp-content/DOC/udxfi9hiq/n8qgmqd5b4o25ye967kvq/
  42. http://hcrg.com.cn/temp/90m4ehxxtgy/ka8h23ffp/
  43. https://pablobrothel.com.ar/local-cgi/jrxl2ncx/
  44. http://viser.in/indexing/browse/
  45. https://rtgpanama.com/eviltwin_sym/attachments/qiyukxs/
  46. http://woodmet.eu/ayeu/y4grqbd/
  47. https://avozdecamacari.com/wordpress/docs/7c6xb589f1cqxjxv335m6g1htflpp4/
  48. https://sylhetibeautiespower.com/wp-includes/212/
  49. http://91idea.cn/28k/paclm/nlyphoos/
  50. http://dev.pearsonsystemofcourses.com/home-v/5ueeswuld943/
  51. http://polotshirts.in/wp-admin/pzjxjd9vy3j/
  52. http://www.dsupay.com/wp-includes/statement/
  53.  
  54. 360wifi.com.cn
  55. 91idea.cn
  56. amberadvisors.com.hk
  57. avozdecamacari.com
  58. dsupay.com
  59. enetra.in
  60. erfa.web.tr
  61. fengxiaopeng.cn
  62. ganeshkulariya.com
  63. gncnacionaldeconsultores.com
  64. gustosoesemplice.com
  65. hcrg.com.cn
  66. hian.vn
  67. hianstore.com
  68. infoquick.co.uk
  69. jegsnet.com
  70. jogjatraveling.com
  71. metube.world
  72. pablobrothel.com.ar
  73. pailingroup.net
  74. partohesab.ir
  75. pearsonsystemofcourses.com
  76. pixelwalkerrproduction.com
  77. polotshirts.in
  78. profblogging.com
  79. qutiche.cn
  80. rezvankosar.ir
  81. rtgpanama.com
  82. scaierp.com
  83. sifesro.com
  84. siyahkalemresim.com
  85. sylhetibeautiespower.com
  86. thietkenoithatthongminh.org
  87. vanphongmau.com
  88. viser.in
  89. woodmet.eu
  90. zabor-pro.store
  91.  
  92. DOCUMENT FILE HASHES
  93. 0243cf093d73e2674286d3abef15ba88
  94. 557571e2f5c9d58a43041fbfefd8cdb4
  95. a95e7e92bb1b841374a0bd7cb7d38b95
  96. d21e1d25494dde142bd9903ecc1cb4e1
  97. d2fa39377308477182334bfbb0db6cee
  98. f0883d1ebd68625a669d9170ee8ac8de
  99.  
  100. ZIP FILE HASHES
  101. 5e6537c953536ec7cbcb6fca63ab626f
  102. 3eda6bc01ae448f3d9eb901596dbef53
  103. 658af3c2cb0f03f5bd78c133a7c6cab5
  104.  
  105. PAYLOAD FILE HASHES
  106. 235eb871cc45547cadf7295bce527a5e
  107. 750b5f92b78b5a74631638818185a9c5
  108. e5231879765859945650d5da7122164d
  109. ec753fb223e613e2e1f18e089849bf03
  110. fa8cfb25e530f508aa8cf0a3e5f7f958
  111. fc871f902715aea1511649abd98ec7ce
  112.  
  113. EMOTET PAYLOAD URLs
  114. http://1999beats.com/torrent/Wg8iT/
  115. http://3ilogics.net/dprj/serviceapi/TU/
  116. http://ashgroup.org/wp-snapshots/Ap/
  117. http://banglashongbad.com/wp-content/sW/
  118. http://blog.zunapro.com/wp-admin/i/
  119. http://brycebrumley.com/wp-admin/IR/
  120. http://buddinosaur.us/wp-includes/gdNzHVmMo/
  121. http://cannabisdiscoverycenter.com/wp-includes/hvzL/
  122. http://carewanderlust.com/wp-includes/zgz0N/
  123. http://carstarai.com/stats/D/
  124. http://codienvietnhat.com/dieuhoavietnhat/oYL/
  125. http://coinketchup.com/wp-content/uploads/Dedzk1U/
  126. http://criterianexpress.com/cgi-bin/q9Ghl/
  127. http://cse-engineer.com/cgi-bin/jm/
  128. http://damaniasons.com/images/1sWs7WMJUW/
  129. http://drdlwallace.com/wp-admin/qo8kgFkc/
  130. http://electronicsvibes.com/wp-includes/A9n/
  131. http://ezisync.com/home/wp-content/tMe/
  132. http://financiamentointeligente.com/wp-content/F/
  133. http://gncnacionaldeconsultores.com/videos/wMS0CC2H/
  134. http://healthcureathome.com/ALFA_DATA/ZD/
  135. http://huaibangchina.com/kic3kc/fq4/
  136. http://packzon.in/wp-content/DFKpVL1b/
  137. http://pattanitkpark.com/gipe2h/BIY/
  138. http://ps.sywwl.cn/web/QQT7D/
  139. http://stockspert.co.in/wp-admin/gxi3lwcB/
  140. http://techinotebook.com/wp-includes/GTu/
  141. http://techinull.com/journal/euW/
  142. http://techisquare.com/blog/zFj/
  143. http://veepeeinternational.co.in/wp-admin/m7/
  144. http://www.bionet.nsc.ru/core/cache/8/
  145. http://www.hnqdyq.com/wp-content/wEr/
  146. http://www.jornco.com/wp-admin/z/
  147. http://www.kheshtkhane.com/wp-admin/d4/
  148. http://www.removepctrojan.com/wp-admin/K/
  149. http://www.sabbathcovenant.com/wp-content/HgFPlMBeU/
  150. http://www.sff3d.com/3d/D/
  151. http://youthhub.tk/icon/DOP1kC/
  152. http://zwawish.com/lagais/w/
  153. https://acupuncture-sandiego.com/Deutsche2/O6/
  154. https://amazinlash.com/huuks/vFkAptcAV/
  155. https://beu-hr.com/9gqqi5eat/K2y/
  156. https://blog.zunapro.com/wp-admin/i/
  157. https://buildmarker.com/wp-content/uploads/N/
  158. https://burbujitasplash.com/sprites/Xp7y/
  159. https://devanyastore.com/wp-content/K/
  160. https://emmaidea.com/wp-includes/q/
  161. https://krishnaoilindustries.com/wp-admin/545HlW/
  162. https://listingera.com/wp-includes/RMM/
  163. https://manhtien.net/wp-includes/Tw3/
  164. https://sandonato.beer/wp-admin/NIpUBO98/
  165. https://shopdocauca.com/wp-includes/CKq8j/
  166. https://theshaywest.com/wp-admin/V/
  167. https://tvinstallationofatlanta.com/wp-includes/nMZ/
  168. https://www.laoyebh.com/phpMyAdmin4.8.5/QY0T/
  169. https://www.moragphotography.co.uk/wp-admin/VEuMa540C/
  170. https://www.mycollegecp.com/wp-admin/W/
  171.  
  172. 1999beats.com
  173. 3ilogics.net
  174. acupuncture-sandiego.com
  175. amazinlash.com
  176. ashgroup.org
  177. banglashongbad.com
  178. beu-hr.com
  179. bionet.nsc.ru
  180. brycebrumley.com
  181. buddinosaur.us
  182. buildmarker.com
  183. burbujitasplash.com
  184. cannabisdiscoverycenter.com
  185. carewanderlust.com
  186. carstarai.com
  187. codienvietnhat.com
  188. coinketchup.com
  189. criterianexpress.com
  190. cse-engineer.com
  191. damaniasons.com
  192. devanyastore.com
  193. drdlwallace.com
  194. electronicsvibes.com
  195. emmaidea.com
  196. ezisync.com
  197. financiamentointeligente.com
  198. gncnacionaldeconsultores.com
  199. healthcureathome.com
  200. hnqdyq.com
  201. huaibangchina.com
  202. jornco.com
  203. kheshtkhane.com
  204. krishnaoilindustries.com
  205. laoyebh.com
  206. listingera.com
  207. manhtien.net
  208. moragphotography.co.uk
  209. mycollegecp.com
  210. packzon.in
  211. pattanitkpark.com
  212. removepctrojan.com
  213. sabbathcovenant.com
  214. sandonato.beer
  215. sff3d.com
  216. shopdocauca.com
  217. stockspert.co.in
  218. sywwl.cn
  219. techinotebook.com
  220. techinull.com
  221. techisquare.com
  222. theshaywest.com
  223. tvinstallationofatlanta.com
  224. veepeeinternational.co.in
  225. youthhub.tk
  226. zunapro.com
  227. zwawish.com
  228.  
  229. EMOTET C2s
  230. http://116.91.240.96
  231. http://167.71.227.113:8080
  232. http://190.85.46.52:7080
  233. http://162.144.42.60:8080
  234. http://202.166.170.43
  235. http://95.216.205.155:8080
  236. http://120.51.34.254
  237. http://103.93.220.182
  238. http://111.89.241.139
  239. http://60.125.114.64:443
  240. http://45.177.120.37:8080
  241. http://185.86.148.68:443
  242. http://75.127.14.170:8080
  243. http://119.92.77.17
  244. http://203.153.216.178:7080
  245. http://172.96.190.154:8080
  246. http://179.5.118.12
  247. http://153.229.219.1:443
  248. http://139.59.12.63:8080
  249. http://115.79.195.246
  250. http://103.229.73.17:8080
  251. http://195.201.56.70:8080
  252. http://190.192.39.136
  253. http://183.77.227.38
  254. http://45.239.204.100
  255. http://192.163.221.191:8080
  256. http://46.32.229.152:8080
  257. http://73.55.128.120
  258. http://113.203.238.130
  259. http://138.201.45.2:8080
  260. http://180.148.4.130:8080
  261. http://77.74.78.80:443
  262. http://115.79.59.157
  263. http://91.83.93.103:443
  264. http://181.80.129.181
  265. http://41.185.29.128:8080
  266. http://178.33.167.120:8080
  267. http://185.208.226.142:8080
  268. http://91.75.75.46
  269. http://86.57.216.23
  270. http://143.95.101.72:8080
  271. http://118.33.121.37
  272. http://116.202.10.123:8080
  273. http://103.80.51.61:8080
  274. http://54.38.143.245:8080
  275. http://50.116.78.109:8080
  276. http://128.106.187.110
  277. http://139.59.61.215:443
  278. http://190.191.171.72
  279. http://58.27.215.3:8080
  280. http://223.17.215.76
  281. http://37.205.9.252:7080
  282. http://37.46.129.215:8080
  283. http://46.105.131.68:8080
  284. http://192.241.220.183:8080
  285. http://24.231.51.190
  286. http://113.161.148.81
  287. http://109.206.139.119
  288. http://118.243.83.70
  289. http://185.142.236.163:443
  290. http://172.105.78.244:8080
  291. http://185.80.172.199
  292. http://190.194.12.132
  293. http://36.91.44.183
  294. http://200.116.93.61
  295. http://192.210.217.94:8080
  296. http://93.20.157.143
  297. http://198.57.203.63:8080
  298. http://78.186.65.230
  299. http://175.103.38.146
  300. http://115.135.158.13
  301. http://113.160.248.110
  302. http://88.247.58.26
  303. http://157.7.164.178:8081
  304. http://67.121.104.51:20
  305. http://74.208.173.91:8080
  306. http://113.156.82.32
  307. http://51.38.201.19:7080
  308. http://14.241.182.160
  309. http://79.133.6.236:8080
  310. http://169.1.211.133
  311. http://202.153.220.157
  312. http://8.4.9.137:8080
  313. http://220.106.127.191:443
  314. http://5.79.70.250:8080
  315. http://37.187.100.220:7080
  316. http://113.193.239.51:443
  317.  
Add Comment
Please, Sign In to add comment