Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #smokeloader #WSH
- C2 indetified by TomasP @0xE9FBFFFFFF
- https://pastebin.com/QpG70u8T
- previous_contact:
- https://pastebin.com/BJzcXqkK
- https://pastebin.com/kBW7nkZ5
- https://pastebin.com/Z7zq0YkW
- https://pastebin.com/b8PkhMyN
- https://pastebin.com/hkskwKvc
- https://pastebin.com/JmthzrL4
- https://pastebin.com/1scwT0f8
- https://pastebin.com/MP3kCSSh
- FAQ:
- https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
- https://research.checkpoint.com/2019-resurgence-of-smokeloader/
- attack_vector
- --------------
- email attach .zipx > js > WSH > GET > exe > AppData\Roaming\Microsoft\Windows\Templates\*.dat
- email_headers
- --------------
- n/a
- files
- --------------
- SHA-256 57dde179404d483ad7c325af4500de2dfd35e7643062f2ae33d7a1cd958be2e8
- File name Договор и рахунок СП ТОВ Радмиртех.zipx [Zip archive data, at least v2.0 to extract]
- File size 32.40 KB (33174 bytes)
- SHA-256 03dcf4f7d4cde69c4775d2ee38e53818f79bd4c55ed4758dab3963af0e891e9c
- File name рах_№5820.xlsx [Microsoft Excel 2007+]
- File size 12.81 KB (13114 bytes)
- SHA-256 64f449cf659d53d01f56c6ccc883486c66a6b113d261635a2462a584bc170ba9
- File name Договор с СП ТОВ Радмиртех.js [ASCII text, with very long lines]
- File size 45.16 KB (46243 bytes)
- SHA-256 4fd6a01b750bd999b55a1f87d8ff383de63e1cd1cf98f54587480f7478af46d1
- File name ioclase.exe [PE32 executable (GUI) Intel 80386, for MS Windows]
- File size 229.50 KB (235008 bytes)
- SHA-256 8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c
- File name 6B79.tmp (ntdll.dll) [Microsoft Visual C++ vx.x DLL]
- File size 1.23 MB (1292192 bytes)
- activity
- **************
- PL_SCR interpremier1998.ru/get/homec/ioclase.exe
- C2 (upd!) homereservecinema.ru/ - down
- kinokritikboss.ru/ - 185.132.53.39
- Smokeload config from hxxtp://kinokritikboss.ru
- https://pastebin.com/bYFkacbg
- *Detects Sandboxie through the presence of a library
- *Checks the presence of disk drives in the registry, possibly for anti-virtualization
- netwrk
- --------------
- [http]
- 185.132.53.39 interpremier1998.ru GET /get/homec/ioclase.exe HTTP/1.1 Mozilla/4.0
- comp
- --------------
- wscript.exe 2060 TCP localhost 185.132.53.39 80 ESTABLISHED
- proc
- --------------
- "C:\Windows\System32\WScript.exe" "C:\Users\operator\Desktop\Договор с СП ТОВ Радмиртех.js"
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Templates\337227.dat
- persist
- --------------
- n/a - payload crash
- drop
- --------------
- C:\tmp\Temporary Internet Files\Content.IE5\R34LXPLS\ioclase[1].exe
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Templates\337227.dat
- C:\tmp\6B79.tmp (ntdll.dll)
- # # #
- https://www.virustotal.com/gui/file/57dde179404d483ad7c325af4500de2dfd35e7643062f2ae33d7a1cd958be2e8/details
- https://www.virustotal.com/gui/file/03dcf4f7d4cde69c4775d2ee38e53818f79bd4c55ed4758dab3963af0e891e9c/details
- https://www.virustotal.com/gui/file/64f449cf659d53d01f56c6ccc883486c66a6b113d261635a2462a584bc170ba9/details
- https://www.virustotal.com/gui/file/4fd6a01b750bd999b55a1f87d8ff383de63e1cd1cf98f54587480f7478af46d1/details
- https://analyze.intezer.com/#/analyses/7da01a78-9bf7-4636-ad3c-8d225603bcb2
- https://analyze.intezer.com/#/analyses/99729c71-4144-40c0-a020-2ebad89f08c5
- https://www.virustotal.com/gui/file/8d16d5caad71aaaaa1479f8477d2928b66581c79932a49a21edf93db2803ab9c/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment