Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Formbook delivered as ISO file. IoCs
- Main object- "rfq4758372421.iso"
- sha256 c9e557ba92ef01c0c77df2a2361b3699838e22abc20368476364230bbae96bdd
- sha1 4afd50e67f2359a55b1ea90b6d7a28d5418d578c
- md5 9f5410a27c6c76a4286f7583b8cf6e71
- Dropped executable file
- sha256 C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.39049\rfq4758372421.exe 066bf79fe3ea032b86c305c05b6b0c9019e6be2778d273d2244d13d6b43fc949
- sha256 C:\Users\admin\AppData\Local\Temp\sqlite3.dll 16574f51785b0e2fc29c2c61477eb47bb39f714829999511dc8952b43ab17660
- DNS requests
- domain www.efserm.com
- domain www.xn--vl2b17e.com
- domain www.xn--ehq36t94sz9t.net
- domain www.neworleansclayworks.com
- domain www.49jiji.com
- domain www.acceptableopqq.site
- domain www.maghreb-design.com
- domain www.qqqav22221.com
- domain www.tanlifinance.com
- domain www.cakehousetrichy.com
- domain www.turkey-real.estate
- domain www.microbioma.online
- domain www.sandiegodogcompany.com
- domain www.cheagt.com
- domain www.5123668.com
- domain www.homegardendealz.info
- Connections
- ip 104.221.162.71
- ip 103.15.234.11
- ip 198.54.117.200
- ip 185.2.5.21
- ip 199.192.22.225
- ip 209.200.154.54
- ip 209.99.40.227
- ip 211.234.63.232
- ip 67.229.163.36
- HTTP/HTTPS requests
- url http://www.49jiji.com/ha/?q4N=F2xXJGBLFO30atyh8hLYpS45O/CvbEiOsJttedgWxyz8GXQFrzF/8hhBucNsKIUzRK5+WA==&rTXd=MLrHw&sql=1
- url http://www.49jiji.com/ha/
- url http://www.xn--vl2b17e.com/ha/?q4N=Ja0mimmxOdKDNHbIG3U6I4NPciMpHdU3O8NMoWvgqBLCeiGgd5LU0u3zDliFQdDNMcqG4g==&rTXd=MLrHw
- url http://www.acceptableopqq.site/ha/?q4N=/SI4Yv00Io0bjGwqQq0CXg4dtvL8XolpU+A2vgN05dxC/9HMha8ZHFwA1WrblmAo9utmOg==&rTXd=MLrHw&sql=1
- url http://www.acceptableopqq.site/ha/
- url http://www.maghreb-design.com/ha/
- url http://www.cakehousetrichy.com/ha/?q4N=MWgscLaoN99KRerENEc99z6QRzwkOUTFUlonXk8Weg6zqfYpqj4B5waqypTpsZ4egTJZtQ==&rTXd=MLrHw&sql=1
- url http://www.cakehousetrichy.com/ha/
- url http://www.maghreb-design.com/ha/?q4N=hv3QID2Cg9CSsaiPPUsfemc+IiV57hyJH/mSmZvdUd7B57db79kfcZ4lOtho0iK0y3JbBg==&rTXd=MLrHw&sql=1
- url http://www.microbioma.online/ha/
- url http://www.sandiegodogcompany.com/ha/?q4N=yNuoEhmMgsSzOsBgc5/PUWM8x6jrzAqE1dKfVzCxG/HAGMvyrOn5vMIsAzCGripEMN7R4Q==&rTXd=MLrHw&sql=1
- url http://www.cheagt.com/ha/
- url http://www.sandiegodogcompany.com/ha/
- url http://www.cheagt.com/ha/?q4N=z0uPcFmmi18A13/CKXOlMfSv+0olK4sq27m+ZnuqLA0se52Yxfqc3/vl7Hni3tbthwGDyw==&rTXd=MLrHw&sql=1
- url http://www.microbioma.online/ha/?q4N=bpzaxzrKYIwKjsgy9cCXvis5WfLJgzvjJM5gcQg3ogYwTYL0msjhNUbNWFokKw/U4Ouq0g==&rTXd=MLrHw&sql=1
- url http://www.homegardendealz.info/ha/
- url http://www.homegardendealz.info/ha/?q4N=T61+qhD16W0YW+4bcGPHLoIEgNkZUf7iKkfB0Y8SLgP4ofSH91cUuAXVvhO8bliZ1EdKgQ==&rTXd=MLrHw
- url http://www.5123668.com/ha/
- url http://www.5123668.com/ha/?q4N=32TRzfy8DkTLKaZ3FfVe0o4FfQ45qlL0BM57yrNdK6C+6GfAmcDD/Jd30Tevcldb8KhiEw==&rTXd=MLrHw
- url http://www.maghreb-design.com/ha/?q4N=hv3QID2Cg9CSsaiPPUsfemc+IiV57hyJH/mSmZvdUd7B57db79kfcZ4lOtho0iK0y3JbBg==&rTXd=MLrHw
- url http://www.acceptableopqq.site/ha/?q4N=/SI4Yv00Io0bjGwqQq0CXg4dtvL8XolpU+A2vgN05dxC/9HMha8ZHFwA1WrblmAo9utmOg==&rTXd=MLrHw
- url http://www.49jiji.com/ha/?q4N=F2xXJGBLFO30atyh8hLYpS45O/CvbEiOsJttedgWxyz8GXQFrzF/8hhBucNsKIUzRK5+WA==&rTXd=MLrHw
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement