ExecuteMalware

2020-07-30 Emotet IOCs

Jul 30th, 2020
3,858
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 26.43 KB | None | 0 0
  1. THREAT ATTRIBUTION: EMOTET
  2.  
  3. SENDERS OBSERVED
  4.  
  5. MALDOC DISTRIBUTION URLS
  6. http://aawen4x4.com.au/4psi_files/private-uz5zad8s0i8es-2dy2awg1x1mj86/special-61789740803-bodOgY/ENv02z1n-tc5utsG7He/
  7. http://aci.serabd.com/aci/available-7yrkemhow-coa7e2c3x33blm/individual-warehouse/fNTyUl-3K98dliM/
  8. http://agacenter.ro/wp-admin/kh9-nhd-95338/
  9. http://altdigital.co.uk/js/private-module/verified-profile/myoigsxqpsim-0z8u685t/
  10. http://anja.nu/closed_disk/external_space/wy22_v458uxzu002uy/
  11. http://aptigence.com.au/random/sites/8z2nfkn8/0rtv45642848544912c2usf979vz4cxfu5y/
  12. http://artabout.gr/signature/XB915BTDKPNB/sybxs3e32bl/2g0ef934479799577067482sxw5w21t5edfq5c0ka/
  13. http://asrijeweler.com/wp-admin/DOC/favf513476009051607a7eqbocb0pg0w97/
  14. http://autobike.tw/image/eo-rgs-077537/
  15. http://bemnessa.com.br/erros/multifunctional_zone/guarded_050947748940_peHQ6sGSipjM/npv_s0u3yv14689w5/
  16. http://benthamstudio.co.uk/wolfsohn.co.uk/closed_resource/open_portal/f2mp_s3869v5/
  17. http://bey12.com/logos/OCT/vk51tln/ifstp4h269839864890zx0jf6prk/
  18. http://bloodcreative.co.uk/Scripts/private-B1PxU-bpyyZM3/lwm1o260shb-cdsu5t590era-ryiK9Kt-Pd9L2ciooPLIEB/192817551-NzXgC6/
  19. http://bloomncare.com/wp-content/esp/rrxjpr/c22y0877995jcg2cdny5/
  20. http://bruset.no/picture_library/multifunctional-zone/corporate-area/33739768-nGH9EnoK/
  21. http://cagev.org/wp-includes/docs/a709cdyuc/
  22. http://capitaladm.com.br/SGQ/nDMepQ/
  23. http://casadorothea.com/cc/c9zt997bbm35_kelmu_resource/interior_forum/rrz3wlvnf_78w8x0/
  24. http://chahooa.com/WP/vdg7nu3ov7/
  25. http://cittadivita.it/fonts/INC/tfcetku53/
  26. http://clanspectre.com/IBmM8PqOJz8pJR/open-box/security-warehouse/306363-leJ4rURzkoZurY8/
  27. http://clinsaobento.com.br/Biblioteca_D/967506_CPEuTmDwki_module/5qrGll4R_K6afSvLLd1PLgd_area/62511521024_pKMvwVHCG/
  28. http://colbydix.com/audio/sgk0nh-yyibwto2l0l-22eaFjtx56-hIzsQUZdrpkW7/interior-forum/562769-gJ1g7wIcupA/
  29. http://comerford.org.uk/book/lu6ic4k2n7prgw-ik9d9k-zone/verified-profile/z7l07yy1tce1-9v3w8swy5yt0y7/
  30. http://commercedusud.com/cgi-bin/tp-yjf18-85615/
  31. http://coneymedia.com/wp-content/multifunctional-zone/guarded-portal/J5fLBVq-M87iwK4IN/
  32. http://cosentinoconsult.com.br/wp-content/289915-NOjxWgPYhzlZ-disk/individual-warehouse/29584277322996-enoiFIpEXgvQ2A5/
  33. http://cosmo.li/GFMI/multifunctional_sector/external_X5zR_GTkqUewl2xeA/973792286194_VTar6/
  34. http://craigdphotography.com/news/ci0a9-6n0-82666/
  35. http://creativeworld.in/picture_library/gz/
  36. http://cyper.org/views/cog8y53oqe/
  37. http://digipro.com.tw/gold99.com.tw/ty-8ej-60/
  38. http://djeffries.com/wp-admin/zs2001-apm-888088/
  39. http://ebe.dk/_bordershacked/hacked/GWSnK-WGkB2u6B6IWWMCy_TbyeojxK-KGB/
  40. http://ebe.dk/_bordershacked/open_zone/security_area/b2jys09lmne9_7x511w3242360/
  41. http://eduprecaro.com/index_htm_files/yMXnSMhR/
  42. http://ehsan.it/Alternative/common_disk/additional_3228698_LqjOy9UH/qp8bsbq9f_9ys4u8vw1/
  43. http://eiburaham.jp/parts/statement/fwdh69wd/
  44. http://ejardine.com/dad/b2a2-3dxj-463/
  45. http://elancla.cl/SpryAssets/93260076883-ZwGwOFtgV-Zs5dBJrc-5uo9pAMS/verified-area/3z5d9q5aq-847szuy07/
  46. http://elementalburn.com/7107012102381-23SZF9DZczYzLB-module/payment/
  47. http://elevationadvertising.com/mobile/Documentation/
  48. http://entouchgraphics.com/modules/rbira-jm8h2-6965/
  49. http://erronsplace.com/multifunctional-box/IccFI/
  50. http://esnconsultants.com/medals/778147664/
  51. http://facetsbusiness.ca/wp-admin/engl/DOC/0s7eun/
  52. http://faroholidays.in/wp-content/ok2-m4gw0-309348/
  53. http://fenlabenergy.com/restore/LFwzpHi/
  54. http://ferafera.com/blueskies/521138744613-UYVWc-section/special-profile/jybevoll7-3uw86w65s74tuv/
  55. http://ferienwohnung-malcesine.de/html/open-resource/individual-warehouse/tigcc-u7w0wy5s16tt/
  56. http://ferramentariahonorio.com.br/PLASTICOS/q9cO97-movSovTXJ7-sector/test-portal/964586063641-7YLEwbuCTyL11LE6/
  57. http://fiberdyneqatar.com/logo/DOC/ql0n5fu/e9pn1647457604mlskhssck1sju/
  58. http://finnigans.org.uk/php/open_zone/special_portal/lpto4lxv5k_y8uszz2w/
  59. http://firemaplegames.com/css/8411573_qhFoHRjICsQmP2d_box/90682778_L3hQOe_profile/091496923549_Mt2hTFCL62LQ5P/
  60. http://firstlineit.co.za/logssite/paclm/
  61. http://flancalfaltd10.com/dist/js/pages/je22cxqsy/
  62. http://foodphotography.in/wp-admin/personal-module/guarded-profile/Zxx3lV2KyHk-Gje898jeLy/
  63. http://foredeckmarine.com.au/assets/open-module/verifiable-DlcdjTE2-z3SB9tp5/91041647-bi9KojGqg/
  64. http://forscene.com.au/images/LLC/kurca3u/r0yr3656933188whnvkchg5e9zmk/
  65. http://fourserious.com/common_module/zij/
  66. http://franelessac.com/blog_1/Overview/ke84h9/lf94416297123919elsfkmtdtyg4/
  67. http://frnossa.com.br/img/PU/
  68. http://fussey.co.uk/wvvw/TpBWheM/
  69. http://gabrielfelipe.com/steiin-admin/lm/5ncuavl6fq/
  70. http://gaoe.com.br/garantiasaude/available-resource/guarded-77nx-3k9ptdi3/637769-IGSyzn/
  71. http://gaoe.com.br/garantiasaude/common_section/4Aqxi_J7ys4ENhUcLJ_portal/pY5pYRUJ_NJg9qN5ubauG9N/
  72. http://garethjames.co.uk/plesk-stat/personal-array/security-s94-wwfhjs4woa0c90e/0ebs0k-8t9x3241tvtvy/
  73. http://gjoweb.it/style/h4lxhwm2Zw_2etRUvvhPo_1X2syZQyo_833Oddln0w/special_warehouse/LYkofahV7_z39sI264aovxk/
  74. http://globdesign.com/cgi-bin/rHfvyiy/
  75. http://goldoni.co.uk/old_sitexxxxxxxxxxxxxxxxxxxxxxxx/invoice/9q40uix/
  76. http://gombui.net/bibliophilia/swift/5gzmh467btdw/795638541389992424j5ka2fhi41hj/
  77. http://goodbad.co.uk/zoeva/open-section/individual-827891-ugLLqPIwclQzf/M6UIqJ9hSDu-twcLI3vu/
  78. http://graduasi.com/wp-content/Overview/s4crxbe969823987hzdz4bhkpgv06900r/
  79. http://grecoson.com/images/tmr21x-p55m-916118/
  80. http://heemaalnews.com/news/protected_sector/corporate_space/g9nz7dvuk2jq_5x5yyw10/
  81. http://herms.com/iAntipodes/o0pa-2x8u-921938/
  82. http://hertronic.com/modules/report/dumhok/
  83. http://homecables.net/wp-content/0205789038156-TbjSB5zYdbVq-module/external-space/4walh-wxv7/
  84. http://horado.ro/wwvvv/vzuWutd/
  85. http://hostmelodia.com.br/lcradioetv/4x1x5u-21i-7655/
  86. http://icacc.com/fcgi-bin/common-53883307959-gexpe8Tlo/external-130834287-Ej78rF/QWI2WRzzl-nahcpL6Npq3G2d/
  87. http://icacc.com/fcgi-bin/multifunctional-khbuqe6ekcp0klpp-697hanmef/security-area/48402530470-L376N7/
  88. http://iensenada.cl/images/rl1h_zz3fqcab9dejfj0g_sector/verifiable_warehouse/YMyGrmfceX78_tGm1jLrt/
  89. http://inbsolutions.co.za/rams/open_X8jGihY_3Gpvxmh3XtKT/guarded_profile/5914710691_iHIsVlDa7gIhbQof/
  90. http://incluschile.cl/naturebeautyspa.com/s3px7_Oss1rD2U_poDlw_e46Zq4IYf/external_owdgcz7ra_w5k/kjQGLcCDVJMp_ux8d4toy60x/
  91. http://infectedarea.com/iwtfy/multifunctional-zone/test-072287610-Sryk0Ri98/03kdh8h4grsqo4op-60u2u17wus026/
  92. http://infomagia.com.br/infomagia/bIx/
  93. http://inmayjose.es/firma/luxart/
  94. http://intelligence.com.sg/support/open_array/additional_Rza5V37_qk6kzm6rJwOixh/92377040671_CuUOCe3H/
  95. http://inzien.me/img/VqSm/
  96. http://irenicinternational.in/website.irenicinternational.in/fFTf/
  97. http://irlenmenezes.com.br/thais/q2cgiibo0rg/8f62669073955108j5obt9dp8n3/
  98. http://isatechnology.com/print/60ka4484819911634268909r5a94sk9qha44yu/
  99. http://iserrat.com/wwvv2/90-1i-3993/
  100. http://ishbudesign.com/vivantphoto/report/y2nfl582427761627221jle7pggwyc62khivc3j611/
  101. http://ishtera.net/swift/w2936888764695127646oqtynli3xg7xsmj8qbtd/
  102. http://itgastaldi.com/wp-includes/b5mzdpb-si-99862/
  103. http://itmas.com.au/includes/personal-array/19685230-yUz7REuzuqRMRnv-8988541872-sf31dxhwaC9U/WsY8uB6aX7-isxs0pvs/
  104. http://jamconsulting.com.au/emarketing2/eTrac/
  105. http://jamesbillingsley.com/photo/oo511lkbwz2k/iv5457767573326884l709fjy5ls6up/
  106. http://jamisonplazanews.com.au/balance/
  107. http://janakre.com/Lf0709YEdM/eTrac/zsf9ft4i8c6p/
  108. http://janoshi.com/cache/ic6su7/
  109. http://jasonb.com.au/wp-includes/12dlpe5/
  110. http://jawara.pro/wp-includes/open_box/close_0298711536_QnJwLpsMIs6/65274365448_5Uqgk9F0bcvFlKdG/
  111. http://jenthornton.co.uk/selfie365.me/payment/gxz5iig0/r2453600824905i06n9m1y1g/
  112. http://jessicaschochphotography.com/joomlatest/parts_service/
  113. http://jestteesn.com/cgi-bin/browse/
  114. http://jetjackinc.com/wp-admin/paclm/93lyz1xaxrc5/g17033349632990yn3foczzqq/
  115. http://jetmundsen.net/public/wu6orx46683709305doo0m9879tm/
  116. http://jimbrashear.com/downloads/Reporting/1xkor79915729116201642hw8honlznv86cctm/
  117. http://jimlutzforohio.com/wp-content/swift/ya70132464563i0fsbynx8oen1/
  118. http://johnstranovsky.com/balance/ceuacg/
  119. http://jonathanfun.com/wp-admin/ZLicu/
  120. http://joswinter.nl/evelaer/12i162369041528686404666hlvx89lok/
  121. http://karenfishermusic.com/scripts/DOC/
  122. http://karenscuts.biz/gallery/public/0soxhi9gcj/eme42u2766527950471035zum0ezi86jhpcg2rk6/
  123. http://katana.co.uk/cgi-bin/caIijOty/
  124. http://kcimage.net/images/report/ivtxrc7ryatx/
  125. http://kecsfila.hu/wp-admin/3j-0wr-000/
  126. http://kecsfila.hu/wp-admin/52ud3r55h/
  127. http://keistadweb.nl/stats/FILE/57zm40646394379430olk0h96ebu/
  128. http://kellymorganscience.com/wp-content/h9mw-ol7o-54/
  129. http://kelomotor.hu/kep_kulcstarto_kicsi/siij1n-wry7-591374/
  130. http://kentsparkman.com/images/payment/bvc284030016506aving9wh6llfaqmc/
  131. http://kereselidze.com/Scan/7bty5xg/
  132. http://kevincameron.net/tfnx/Reporting/
  133. http://kevsun.org/fonts/report/kbvlhu4o/g97827940366v7x8vn9crvlv50dkj/
  134. http://keyesfamily.net/john/FILE/
  135. http://khaiy.com/cgi-bin/attachments/og2n94859134863356kubxol0r0gyldf1ob6789/
  136. http://kmklawllp.co.ke/bin/closed_disk/verifiable_warehouse/4454466527_R7Ojkf/
  137. http://kriomed.uz/admin/attachments/dpqccegbfdt/
  138. http://ktbcs.co.uk/f07w_PzAMTx0KZ2JP_sector/verified_warehouse/7445119449_MBxcKPb9/
  139. http://kultfitness.com/wp-includes/XubvOifYz/
  140. http://kupkes.net/vddb/esp/
  141. http://lacasamia.co.uk/z8ju268-oz5x-978031/
  142. http://lancon.com.au/guest/public/
  143. http://lansec.com.br/protected_pyig_mld1w/test_cloud/720536_50jkb/
  144. http://laschuk.com.br/wordpress/docs/2gge4ej/
  145. http://laurenebohn.com/lm/szfb5c54/
  146. http://ldgcorp.com/6aqjxtad-7c1-01/
  147. http://legend.nu/wordpress/parts_service/
  148. http://leong.ws/Scouting.my/closed-Rpng-iupUpmO/open-portal/vjlva-wy3z97y8ww/
  149. http://lifegiva.com/wp-content/ibrKl/
  150. http://lighthouse-safety-solutions.co.uk/backup_oldfiles/sites/8lf9auekk/53kqs423125233926215bryrb9npsyy/
  151. http://lindasfamilytrees.com/gedcomfiles/nw7gitwu6/0oak72363624345bs7okhmb3/
  152. http://lindnerelektroanlagen.de/pages/Overview/teei81i/
  153. http://linesoft.fr/include/INC/
  154. http://lingledist.com/cgi-bin/LwnWMVaY/
  155. http://lmimpresiones.cl/cgi-bin/299024650/
  156. http://loboelhouwers.nl/thumbs/cm/css/72405/l02wb5/
  157. http://logotypfabriken.se/wp-content/balance/tdfu46666340722745c16g659jfn01hq5gs/
  158. http://lojajosemar.com.br/site/hdg-gux-5698/
  159. http://lokeshullamkecskemet.hu/mail/eTrac/547jbn/
  160. http://lubbocksss.com/OldSite/payment/ki1u109375710aw5vp7o5319jq/
  161. http://luchies.com/scripts_index/attachments/df74rpt7r/
  162. http://lucienc.net/opengarden/ECTe/
  163. http://luczakj.c0.pl/referencje/esp/uwhqg2668285910mp4wq347u9x5qpu/
  164. http://luggares.com/picture_library/esp/nw523892229086842bdpbyjxvyq5fz49g/
  165. http://luilao.com/paclm/n389338722w6hiss0ntgl06s4672y/
  166. http://luizazan.ro/wp-admin/uk7-u6-9136/
  167. http://lunapizza.com/swift/
  168. http://lunny.com/fogkbv-rl-843138/
  169. http://madebyrob.net/photosbyrob.net/balance/71shau33243030126802pwjsvj580zyh9imi/
  170. http://magdork.com/audio/lm/
  171. http://mcomlhr.com/cgi-bin/qpds-5ub-25676/
  172. http://megasolucoesti.com/css/multifunctional-zone/6p6fz5872xavk-l6kkagnmmxx-yrjo5qol2oj7pb-9woqaqbj/qwbxe9tcbih-8swx728z44/
  173. http://mgregoire.net/cgi-bin/LYbx/
  174. http://mifaingenieros.com/wp/swift/
  175. http://modbecloset.com/bigfatbratbabydog/16abyxdj3gclguwp_yvgtghv2n_section/guarded_kt9q_1v4f83ev7n/0533420167_dquy7ucns/
  176. http://mydcareahomes.com/RealEstate/RjBNr/
  177. http://ngcdfkibra.go.ke/mail/sRxXqv/
  178. http://nuwagi.com/old/EOBPpCJ/
  179. http://oikotexnia-a-o.gr/abante/1xitqhrq/
  180. http://omeryener.com.tr/stylus/NpWCrMKv/
  181. http://oshop.es/test/common-296122707-8q58yAwAsJl/verified-cloud/d4aksuofzr7k-7652zzxw6/
  182. http://perlahuelva.es/ENG/common-disk/security-cloud/ypr52ekq-060y/
  183. http://puertosalsa.cl/js/multifunctional-section/verifiable-portal/1v5sq78-t50784t844t2/
  184. http://rafamora.net/wp-includes/z05-bcc-341722/
  185. http://randradeseguros.com.br/produtos/QeDYt/
  186. http://renkegitim.com/cgi-bin/INC/90z6a8mhmv/
  187. http://rhema.com.sg/cgi-bin/YxaR/
  188. http://scmasabacus.com/js/common_8TzIKrXm_zlpCg8v2/guarded_portal/J6EYoJuYoQ_0iovJIIH/
  189. http://sipesv.org./administrator/Documentation/
  190. http://slanacom.si/css/Scan/9lutb0me/
  191. http://stechman.com.br/afm/3s-epxi-43/
  192. http://stonehouseevents.com/css/MIRKYGInc/
  193. http://sugarcoatedspider.co.uk/awstats-icon/iwq5-ge0r-6687/
  194. http://tecnozam.cl/wp-includes/Document/hdbyvnff8una/
  195. http://teploservis.info/system/Reporting/8g1986539134vsifajldytp3h/
  196. http://terichmir.com.pk/wp-includes/sTA/
  197. http://trainingbodies.com/webmaster/available_disk/security_8n73pig8yadzs_loc5300i9/mvk135_yttzs0vy03155/
  198. http://uniteddatabase.net/wp-content/hmy-a6-390220/
  199. http://utah211.org/prototype_dev/Document/
  200. http://vailventures.com/cgi-bin/Document/iwq3rgt2iaj/
  201. http://vasinfo.com.br/uploads/INC/toqn40xxa/3dymlsk3665192952125550346k0hx52auspx56deh/
  202. http://vidrorapido.com.br/banco/balance/l346g0rjbvf/kq72860476736qcu4tffv2rty2e9ypk/
  203. http://viportal.co/shoock/FILE/
  204. http://vtechnocrat.com/admin786/dgfyo/
  205. http://w3art.com/dtla/common_module/guarded_profile/r0tpg3s_x5443w99/
  206. http://w4icw.com/Website/parts_service/
  207. http://witje.be/dutchphotozone/LudZ/
  208. http://www.acinutrilife.com/test/report/
  209. http://www.behnasan.com/wp-content/73F13HW4/n4f8xilqk/
  210. http://www.calabria.com.pk/demo/zl6rm3schv_ar6j935e_module/verifiable_area/549884915170_5uveh3TmsGYeA/
  211. http://www.cbi.com.eg/wp-content/multifunctional-box/479140351167-KQZikOmjyHvaK-forum/w152yv5-w0w0s0/
  212. http://www.cuestionspirits.com/index_files/5RIHT/skjlee8h19/3r3875389870118i19wzyxkdq3r/
  213. http://www.ekramco.ir/english/templates/docs/
  214. http://www.ffval.hr/cgi-bin/attachments/
  215. http://www.fuba.com.au/manager/closed_box/guarded_warehouse/FKAUwxgXL9Q_w10knzlpgci/
  216. http://www.fulltel.it/wp-content/multifunctional-section/corporate-profile/8hEZ4c-0Mk2L6qu/
  217. http://www.gammatron.com.au/ajd/invoice/mpze2u9/
  218. http://www.industrialequip.net/cgi-bin/personal-152721572730-gls250/corporate-space/2ws4cr0p8pvwbg-u028sux64w2/
  219. http://www.intercont.eu/own/swift/1berhkyl/
  220. http://www.irishcarsagadir.net/images/17nlh-arj-19161/
  221. http://www.isisjade.com/wp-includes/INC/egklww4213856084mdhayqgk1zafvni4vpb/
  222. http://www.janoshi.com/cache/ic6su7/
  223. http://www.kyesgroups.com/cgi-bin/i0boam6/
  224. http://www.lerasole.it/wp-content/rlcju-gu-290417/
  225. http://www.linesoft.fr/include/INC/
  226. http://www.lojajosemar.com.br/site/hdg-gux-5698/
  227. http://www.loveslap.com/wwvv2/Gm/
  228. http://www.magoenmadrid.com/Arturo/w3j1xnp11/
  229. http://www.magsoft.it/blog_img/lpary2-lu-94322/
  230. http://www.puertosalsa.cl/js/vd7tdotu-782z1-95/
  231. http://www.rsplot.com.br/iwKAZkA//
  232. http://www.smarthub.ws/generated/personal-module/additional-space/94807247323-joDV3JKUi7TyvShK/
  233. http://www.spcc.cl/OLDCODES/closed_sector/interior_portal/573409027_txvpo6F3Wd/
  234. http://www.svkn.at/drupal/protected-sector/corporate-warehouse/54901370265050-o5vj09BJqgAyjn/
  235. http://www.vpinversiones.cl/img/report/fa7sges/
  236. http://yamnadlan.com/ynpw/zvjg-vo-892/
  237. https://adhd.org.sa/sub_we-are/z48rpev90d/0bjo209677710ax9i7w4fskut4t11t/
  238. https://backroom.co.nz/1080/Documentation/
  239. https://chaoscopia.com/Scripts/sites/g74vm9gs/4b883927243019016csfy17fxlfe44ym3byboz/
  240. https://dewide.com.br/cursoculinariasaudavel/emv/
  241. https://flamesofrichmond.co.uk/img/eccgtgg/xnrrl340046272572dvmdyu8twrre46czm6vz/;/
  242. https://gghekking.nl/ebanking/34ub1ibpctmc/zkoke5316762927778879wsc8yrs40n4xs7e5g0wh/
  243. https://giantsinthesky.com/cgi-bin/sPeel/
  244. https://goldilockstraining.com/wp-includes/parts_service/tyv2ng/
  245. https://healinghandsonthemove.com/wp-content/balance/
  246. https://ingesolutions.com/estructuras-livianas/eTrac/1xlyekqq33g/
  247. https://irenicinternational.in/website.irenicinternational.in/fFTf/
  248. https://jeffdahlke.com/css/Reporting/po3x708837819192166196fun7k976gnpv/
  249. https://jrvservices.com.br/JRV_ANTIGO/36qkwciosy6qs-1dxjawwaw-zone/interior-space/QzveCXbS-5G5htj2uNr5dj/
  250. https://kerosky.com/wp-content/swift/
  251. https://kontaci.com/cgi-bin/browse/nfy6gx113300005267668887eps7evqjczwlh1eyi8mx1d/
  252. https://lotuspolymers.com/wp-includes/gGwipB/
  253. https://meinhaarzauber.de/cgi-bin/jgGjVSz/
  254. https://nypthealing.com/wp-includes/open_zone/test_space/gl3_0u3zuy33ws/
  255. https://wb0rur.com/certificates/ot4beu0i-2riv-894132/
  256. https://witje.be/dutchphotozone/LudZ/
  257. https://www.clinicconsortium.org/wp-admin/m6g965115517737951781n53xtjvr52/
  258. https://www.cwa.mx/binar/paclm/b6sh9nce6p/
  259. https://www.doblementa.com/fuentes/closed_0943392_VL4ftKJmKGm2RI/guarded_area/1594173_HUfYRx/
  260. https://www.fizion.nl/wp-content/HOXgqVqWp/
  261. https://www.isatechnology.com/print/60ka4484819911634268909r5a94sk9qha44yu/
  262. https://www.jsdg.com.br/cgi-bin/attachments/
  263. https://www.kriskate.com/upload/private_array/interior_cloud/43197515760197_AFdBR5sJxTTXa/
  264. https://www.kunsttrip.nl/Connections/personal_615619753_43j6pbFo/individual_space/PIhytuTHz_M7qsKb96cddi/
  265. https://www.lgpass.com/images/closed_resource/security_portal/575383_FcZjBnodcIXU/
  266. https://www.libertolaw.com/test/UDMTR/
  267. https://www.lokaunet.com.br/hotel-normandie/1947/nky97u3/4ea1x89704023169y828lkwtz0es1avz/
  268. https://www.ranking-site.de/picture_library/browse/zsaiowa5owa2/
  269. https://www.serviluz.com/leopardo/INC/ysftnf3tkn/
  270. https://zasobygwp.pl/redirect?sig=f88a745272587f579e8ce173b9952c32f161eb9733ec249031b854898cd62375&url=aHR0cDovL2RhbmlydmlucGhvdG9ncmFwaHkuY29tL3dlZGRpbmcvRklMRS94OHp5Nm9nNi8=&platform=desktop&brand=wp/
  271.  
  272. DOCUMENT FILE HASHES
  273. 13a4708ba3c489ad457315f888361347
  274. 4f22560ef839a2cbdf19881d01eafda9
  275. 8e188e9d2fda2c985e729ae3dd76aa3a
  276. a81ec6aeaa10909b8117bc2f72ee9861
  277. bb53f4dc7ad6331ea849f3351dd8de67
  278. e285ce98290ef514e147ab84909a9500
  279. e34ccc7f59a2795d84d8a5290db48352
  280.  
  281. PAYLOAD FILE HASHES
  282. 13ff330a24b731b44b17f82a1af91a92
  283. 18df1e82cadbdefbc8b26d8a65c3bf78
  284. 226642de1b8f47b937b5d2e87d1f47ce
  285. 261c26a6581db763d7a7f9e1dbc60421
  286. 2c1ed05d76392c67f79dc0ec34503bb2
  287. 61664591c15d018ef70c1f8e6fea062e
  288. 69ab81ef985a3ad5d04dfbca10bd5bea
  289. 6ab241a84ffe708a1c46ca017024e591
  290. 8a42bd7641ec6c52cf23350cd85a7768
  291. ad0838e5a906117df6240c124da3873c
  292. d949fcb075e13396f2b6f53c61049595
  293. e46a4e31d0a08b65b1450f11b4951fda
  294. f11d578e9c0122a01a7848442b9cac99
  295. f9f3259b684c04c9815f07cc462eca41
  296.  
  297. EMOTET PAYLOAD URLs
  298. http://amventas.com/public/iu1c_vtucu_ruec/
  299. http://bangkokglass.com/wp-admin/XPfdRq/
  300. http://barkhone.ir/logs/Tqh/
  301. http://bartboutens.nl/wp-admin/no77z_k3_azs/
  302. http://binaboud.com/picaboud/images/4k9w0176085/
  303. http://blscomputerworks.com/journal/nkk7135571/
  304. http://bostonseafarms.com/images/30v/
  305. http://charihome.com/wvw/jP004459/
  306. http://deegit.com/includes/4NO/
  307. http://defiteqazerbaycan.com/admin/1arj7yzuc64148024/
  308. http://diavlos6.gr/radio/CQDun43o75761/
  309. http://ebe.dk/_bordershacked/hacked/cZJi/
  310. http://etawala.com/BACKUP/egNICnA/
  311. http://fericire.zamira.ro/wp/iMC97lw278iw91398794/
  312. http://goldenstatetow.com/peradice.com/jk_le4_xip2a7s6/
  313. http://highlevelphoto.co.uk/Clients/7uf_yp_76rqsyz/
  314. http://instamal.com/eazylot.com/ScVIwfSxR/
  315. http://itbparnamirim.org/wp-admin/vx_o492_ej/
  316. http://itmh.org/wwvvv/e0aa_nir08_vf/
  317. http://itvconsult.com/d3z_knd_g4/
  318. http://jabenitez.com/ts/8okvz_je_lpg9ty/
  319. http://jamesgrantguitar.com/wp-content/wyjh0_a_qa6o72zg/
  320. http://jdelectronics.com.au/1e8nq_ij3_tq76ahy/
  321. http://joeljustice.com/images/OM4AD/
  322. http://johnsonlam.com/images/KO2l8V/
  323. http://jolapa.com/bobby/ll5P/
  324. http://joshuasjewelry.com/feed/JF5x9530/
  325. http://jothay.com/ClientBin/dyMrK85523/
  326. http://juniorsplayground.net/wp-content/b40e81/
  327. http://katebayless.com/3WGf/
  328. http://ke-s.com/wwvv2/x6_po_l4bvtd2d/
  329. http://klem.com.pl/tester/ntts3_j_3cgou2/
  330. http://kmgusa.net/_Media/vcpg_k56w_8d5/
  331. http://kompkon.com/cgi-bin/OAnF682/
  332. http://librero.xyz/Scripts/3y_m0cbe_lpgoj7z/
  333. http://mikeflavell.com/cgi-bin/wzra_mg_1s6h9/
  334. http://moncheznous.ca/js/4w3ze_f_sj/
  335. http://mosdk.com/img/bg/css/f1_ski_fpm2/
  336. http://mosquitohawk.net/cgi-bin/bdk1_70_vsstep/
  337. http://motorcomunicacion.com/wp-admin/0_35_8ebbd/
  338. http://nixoid.com/assets/oHy758/
  339. http://philosopherswheel.com/mizeo9/y_6pth_ymkgef/
  340. http://saangberg.com/wp-includes/u_a_vn/
  341. http://scoenuganda.org/wp-admin/k_fhsvc_wni2zxzrc/
  342. http://surguy.com/assets/1yP/
  343. http://thehenkins.com/cgi-bin/qlGK8wk6ll1458113/
  344. http://virtualmillers.com/corvette/dTAy/
  345. http://webappbr.com/wp-admin/ha_s5_3wf/
  346. http://whatsappsenderpro.com/Videos/4wl_0q0m_g61c3/
  347. http://www.bladimirindustrial.com/light_php/5qj6/
  348. http://www.cankoc.com/images/XoDbXe0X6/
  349. http://www.cotrafina.com/wp-content/xrmq_7ug_ttv/
  350. http://www.earnmoneynow.nl/wp/wp-content/kuZFc658768/
  351. http://www.faulidi.com/oqFagLcs/
  352. http://www.fedaicoskun.com/wp-includes/DbkL403/
  353. http://www.geodesign07.com/wp-content/ni9tn_7_6aiui/
  354. http://www.ifitmoves.net/option-tree/age9k_r7p_0l2/
  355. http://www.inkarainbow.com/antiguo/hLm9K565/
  356. http://www.moverviseu.com/wp-content/jl173/
  357. https://cimsjr.com/hospital/lowxvel44660441/
  358. https://denizyahci.com/asset/4z8qjblu71664/
  359. https://fotoobjetivo.com/wp-content/m_57ss_tqngo4r/
  360. https://itkossi.com/backup/q6bk_pwr0_wevmq/
  361. https://quickwood.com/wp-content/kiw586pbrk520193/
  362. https://sparkcreativeworks.com/spark/QoZqtWjUs/
  363. https://webpresario.com/now/Marck-Script/c3j0x_6_8z2g0sdd/
  364. https://www.knightlycomputing.com/old/wp-content/cache/minify/m_m9_mj/
  365. https://www.merlincolor.com/stylesheets/46_b_ez5p/
  366.  
  367. EMOTET C2s
  368. http://47.146.117.214
  369. http://62.108.54.22:8080
  370. http://212.51.142.238:8080
  371. http://190.160.53.126
  372. http://87.106.136.232:8080
  373. http://74.208.45.104:8080
  374. http://121.124.124.40:7080
  375. http://124.45.106.173:443
  376. http://76.27.179.47
  377. http://210.165.156.91
  378. http://61.19.246.238:443
  379. http://81.2.235.111:8080
  380. http://169.239.182.217:8080
  381. http://181.230.116.163
  382. http://139.130.242.43
  383. http://46.105.131.87
  384. http://139.59.60.244:8080
  385. http://222.214.218.37:4143
  386. http://41.60.200.34
  387. http://200.55.243.138:8080
  388. http://24.234.133.205
  389. http://190.55.181.54:443
  390. http://189.212.199.126:443
  391. http://93.156.165.186
  392. http://62.138.26.28:8080
  393. http://62.75.141.82
  394. http://176.111.60.55:8080
  395. http://168.235.67.138:7080
  396. http://109.117.53.230:443
  397. http://5.196.74.210:8080
  398. http://162.154.38.103
  399. http://152.168.248.128:443
  400. http://83.110.223.58:443
  401. http://95.9.185.228:443
  402. http://180.92.239.110:8080
  403. http://209.141.54.221:8080
  404. http://37.187.72.193:8080
  405. http://113.160.130.116:8443
  406. http://85.59.136.180:8080
  407. http://79.98.24.39:8080
  408. http://91.231.166.124:8080
  409. http://185.94.252.104:443
  410. http://108.48.41.69
  411. http://95.179.229.244:8080
  412. http://71.208.216.10
  413. http://93.51.50.171:8080
  414. http://78.24.219.147:8080
  415. http://24.179.13.119
  416. http://200.41.121.90
  417. http://153.126.210.205:7080
  418. http://104.236.246.93:8080
  419. http://46.105.131.79:8080
  420. http://201.173.217.124:443
  421. http://50.116.86.205:8080
  422. http://116.203.32.252:8080
  423. http://157.245.99.39:8080
  424. http://109.74.5.95:8080
  425. http://203.153.216.189:7080
  426. http://87.106.139.101:8080
  427. http://137.59.187.107:8080
  428. http://110.145.77.103
  429. http://47.153.182.47
  430. http://95.213.236.64:8080
  431. http://24.43.99.75
  432. http://209.182.216.177:443
  433. http://173.91.22.41
  434. http://5.39.91.110:7080
  435. http://75.139.38.211
  436. http://91.211.88.52:7080
  437. http://37.139.21.175:8080
  438. http://162.241.92.219:8080
  439. http://104.131.11.150:443
  440. http://70.167.215.250:8080
  441. http://104.131.44.150:8080
  442. http://103.86.49.11:8080
  443. http://65.111.120.223
  444.  
  445. http://201.235.10.215
  446. http://198.57.203.63:8080
  447. http://163.172.107.70:8080
  448. http://172.105.78.244:8080
  449. http://107.161.30.122:8080
  450. http://203.153.216.182:7080
  451. http://37.46.129.215:8080
  452. http://201.214.108.231
  453. http://178.33.167.120:8080
  454. http://181.113.229.139:443
  455. http://192.210.217.94:8080
  456. http://24.157.25.203
  457. http://94.96.60.191
  458. http://157.7.164.178:8081
  459. http://75.127.14.170:8080
  460. http://189.146.1.78:443
  461. http://190.164.75.175
  462. http://192.241.220.183:8080
  463. http://190.55.233.156
  464. http://91.83.93.103:443
  465. http://144.139.91.187
  466. http://87.106.231.60:8080
  467. http://140.207.113.106:443
  468. http://139.59.12.63:8080
  469. http://181.167.35.84
  470. http://50.116.78.109:8080
  471. http://74.208.173.91:8080
  472. http://46.49.124.53
  473. http://81.17.93.134
  474. http://81.214.253.80:443
  475. http://46.32.229.152:8080
  476. http://41.185.29.128:8080
  477. http://190.111.215.4:8080
  478. http://216.75.37.196:8080
  479. http://37.70.131.107
  480. http://181.143.101.19:8080
  481. http://115.79.195.246
  482. http://192.163.221.191:8080
  483. http://87.252.100.28
  484. http://181.164.110.7
  485. http://89.108.158.234:8080
  486. http://105.209.239.55
  487. http://181.134.9.162
  488. http://185.142.236.163:443
  489. http://195.201.56.70:8080
  490. http://78.189.111.208:443
  491. http://113.160.180.109
  492. http://5.79.70.250:8080
  493. http://37.208.106.146:8080
  494. http://179.5.118.12
  495. http://203.153.216.178:7080
  496. http://177.144.130.105:443
  497. http://75.139.38.211
  498. http://177.37.81.212:443
  499. http://77.74.78.80:443
  500. http://78.188.170.128
  501. http://212.156.133.218
  502. http://113.161.148.81
  503. http://46.105.131.68:8080
  504. http://51.38.201.19:7080
  505. http://143.95.101.72:8080
  506. http://212.112.113.235
  507.  
  508. http://24.249.135.121
  509. http://185.94.252.13:443
  510. http://149.62.173.247:8080
  511. http://50.28.51.143:8080
  512. http://80.249.176.206
  513. http://5.196.35.138:7080
  514. http://190.17.195.202
  515. http://143.0.87.101
  516. http://190.147.137.153:443
  517. http://181.30.69.50
  518. http://51.255.165.160:8080
  519. http://190.96.118.251:443
  520. http://72.47.248.48:7080
  521. http://178.79.163.131:8080
  522. http://212.231.60.98
  523. http://187.162.248.237
  524. http://2.47.112.152
  525. http://68.183.190.199:8080
  526. http://192.241.143.52:8080
  527. http://77.55.211.77:8080
  528. http://87.106.46.107:8080
  529. http://191.182.6.118
  530. http://189.1.185.98:8080
  531. http://93.151.186.85
  532. http://204.225.249.100:7080
  533. http://177.73.0.98:443
  534. http://137.74.106.111:7080
  535. http://219.92.13.25
  536. http://89.32.150.160:8080
  537. http://82.240.207.95:443
  538. http://190.6.193.152:8080
  539. http://190.163.31.26
  540. http://190.181.235.46
  541. http://114.109.179.60
  542. http://70.32.84.74:8080
  543. http://94.176.234.118:443
  544. http://77.90.136.129:8080
  545. http://217.13.106.14:8080
  546. http://212.71.237.140:8080
  547. http://82.196.15.205:8080
  548. http://181.129.96.162:8080
  549. http://104.131.103.37:8080
  550. http://83.169.21.32:7080
  551. http://177.139.131.143:443
  552. http://187.106.41.99
  553. http://104.131.41.185:8080
  554. http://192.241.146.84:8080
  555. http://170.81.48.2
  556. http://181.120.79.227
  557. http://68.183.170.114:8080
  558. http://177.72.13.80
  559. http://61.92.159.208:8080
  560. http://12.162.84.2:8080
  561. http://186.70.127.199:8090
  562. http://45.161.242.102
  563. http://179.60.229.168:443
  564. http://70.32.115.157:8080
  565. http://191.99.160.58
  566. http://172.104.169.32:8080
  567. http://177.66.190.130
  568. http://71.50.31.38
  569. http://203.25.159.3:8080
  570. http://185.94.252.12
  571. http://217.199.160.224:7080
  572. http://177.74.228.34
  573. http://177.144.135.2
  574. http://190.194.242.254:443
  575. http://202.62.39.111
  576. http://201.213.156.176
  577. http://92.23.34.86
  578. http://185.94.252.27:443
  579. http://104.236.161.64:8080
  580. http://181.167.96.215
  581. http://111.67.12.221:8080
  582. http://144.139.91.187:443
  583. http://186.250.52.226:8080
  584. http://46.28.111.142:7080
  585.  
  586. SUPPORTING EVIDENCE
  587. All of the Word document files were from our honeypot or downloaded directly from URLs.
  588. I manually extracted many of the payload URLs and others were downloaded from URLHaus.
  589. All C2 addresses were extracted manually.
Advertisement
Add Comment
Please, Sign In to add comment