Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Main object- "696164927_4408052.doc"
- sha256 80a836c861b6a5d045d85aa9d3091035691b769ebdcd3b4de781f47c257049e7
- sha1 c7c4c02cb7c6ddfc8a6f7b75c6928b913b6a1792
- md5 929116540242d88367af42f66e1a0336
- Dropped executable file
- sha256 C:\Users\admin\395.exe 6c1be09c8f2343a64df37ebea3c52cb23917f477a07ebae55dfb395ef777551a
- sha256 C:\Users\admin\AppData\Local\soundser\8jEqrsz01GBzvB.exe dce3f2c289e119e58dc2daebcaa85fe0395a85cb332fa445594889daf162933f
- DNS requests
- domain garammatka.com
- Connections
- ip 187.188.166.192
- ip 103.228.112.39
- ip 187.137.162.145
- ip 88.215.2.29
- ip 65.49.60.163
- ip 45.33.35.103
- HTTP/HTTPS requests
- url http://garammatka.com/cgi-bin/o569U/
- url http://88.215.2.29/teapot/
- url http://187.137.162.145:443/nsip/nsip/ringin/merge/
- url http://65.49.60.163:443/psec/devices/
- url http://45.33.35.103:8080/img/rtm/
- HTTP requests wrote in MalDoc Macro
- http://garammatka.com/cgi-bin/o569u/
- http://rinconadarolandovera.com/calendar/5n5wy/
- http://gamvrellis.com/media/heumx/
- http://hadrianjonathan.com/floorplans/voec/
- http://warwickvalleyliving.com/images/wmgn/
- Reference
- https://app.any.run/tasks/620abd44-7403-4c1c-880c-d811b133ce41
Add Comment
Please, Sign In to add comment