Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #smokeloader #zip #7z #polyglot #EXE
- https://pastebin.com/UfW73LSg
- previous_contact:
- https://pastebin.com/e46KzBWE
- https://pastebin.com/xEwN5JPc
- https://pastebin.com/GMwv38g4
- https://pastebin.com/DgFvarG0
- https://pastebin.com/AayUSaXq
- ...
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.smokeloader
- https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
- attack_vector
- --------------
- email attach .zip (polyglot) > .7z > .exe > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Thu, 09 Nov 2023 14:23:10 +0200
- Subject: Fw[2]: Акт звірки. та рахунок
- From: Артем Жукович <artem_arma@ukr.net>
- Received: from frv196.fwdcdn.com ([212.42.77.196])
- Message-Id: <1699532580.0690892000.rg8wfvhn@frv50.fwdcdn.com>
- X-Mailer: mail.ukr.net 5.0
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 4606430cab74535328d1378cc2a8f82531290dc70dd08b49f08fc50cbe115a7e
- File name акт_списання_Б-00003564_вiд_08.11.23 (1).zip [Zip archive data, at least v2.0, !polyglot]
- File size 149.50 KB (153090 bytes)
- SHA-256 6175d5231849905e3f35015bc80fe72901018be6d16ca516c5de0477ad6ed7e2
- File name акт списания та .рахунок [7-zip archive data, version 0.3]
- File size 148.92 KB (152497 bytes)
- SHA-256 6fe8c9bfed9abde0c5ccf98f9307da5e24eb9601788274593b3e30b1fbe7f53a
- File name акт_списання_Б-00003564_вiд_07.11.23.XLS.exe [ Win32 Executable MS Visual C++ (generic) ]
- File size 316.50 KB (324096 bytes)
- SHA-256 9f1dcbc35c350d6027f98be0f5c8b43b42ca52b7604459c0c42be3aa88913d47
- File name акт списання №Б-00003564 від 30.10.23.xls [ null bytes ]
- File size 8.00 KB (8192 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR email_attach
- C2
- againandagaingmorder { .ru/index.php
- colbasaibliny { .ru/index.php
- cafewithcraftbeer { .ru/index.php
- mymozhemesche { .ru/index.php
- antidomen { .by/index.php
- foodplacecafe { .by/index.php
- pozvonimnepozvoni { .ru/index.php
- ximpromooo { .ru/index.php
- narkotikizlo { .ru/index.php
- yavashakrysha { .ru/index.php
- etovamnepomozhet { .ru/index.php
- myvasocheunlyubim { .ru/index.php
- spasibozavsedruziya { .ru/index.php
- vymnenravites { .by/index.php
- propertyofiranmy.ir/index.php
- sportlotovukraine { .ru/index.php
- vseochenxorosho { .ru/index.php
- nekuritebambuk { .ru/index.php
- netwrk
- --------------
- 193.106.175.11 againandagaingmorder{ .ru 80 HTTP POST /index.php HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
- 195.123.219.57 foodplacecafe{ .by 80 HTTP POST /index.php HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
- 195.123.219.57 spasibozavsedruziya{ .ru 80 HTTP POST /index.php HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
- 193.106.175.11 nekuritebambuk{ .ru 80 HTTP POST /index.php HTTP/1.1 (application/x-www-form-urlencoded) Mozilla/5.0
- comp
- --------------
- акт_списання_Б-00003564_вiд_07.11.23.XLS.exe 193.106.175.11 80 ESTABLISHED
- акт_списання_Б-00003564_вiд_07.11.23.XLS.exe 195.123.219.57 80 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\акт_списання_Б-00003564_вiд_07.11.23.XLS.exe
- {another context}
- C:\Windows\system32\taskeng.exe {2E377A9D-6F27-4851-8DA3-7F8987837E69} S-1-5-21-2085049433-1067986815-1244098655-1000:AHLBRYJO\operator:Interactive:[1]
- C:\Users\operator\AppData\Roaming\baaubru
- persist
- --------------
- \Firefox Default Browser Agent B533C761E196FE86 C:\Users\operator\AppData\Roaming\iejtdvv [task]
- drop
- --------------
- акт списания та .рахунок
- акт_списання_Б-00003564_вiд_07.11.23.XLS.exe
- Рахунок_Б-00003564_вiд_07.11.23.XLS.exe
- # # # # # # # #
- additional info
- # # # # # # # #
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/4606430cab74535328d1378cc2a8f82531290dc70dd08b49f08fc50cbe115a7e/details
- https://www.virustotal.com/gui/file/6175d5231849905e3f35015bc80fe72901018be6d16ca516c5de0477ad6ed7e2/details
- https://www.virustotal.com/gui/file/6fe8c9bfed9abde0c5ccf98f9307da5e24eb9601788274593b3e30b1fbe7f53a/details
- https://analyze.intezer.com/analyses/c1cd6523-168b-4acb-a5b6-345ad3543abc/dynamic-ttps
- https://www.virustotal.com/gui/file/9f1dcbc35c350d6027f98be0f5c8b43b42ca52b7604459c0c42be3aa88913d47/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement