Advertisement
jroosen

Emotet Malware URLs 03/01/18

Mar 1st, 2018
13,435
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.48 KB | None | 0 0
  1. #Emotet Malware document links/ IOCs 03/01/18 18:15 EST
  2.  
  3. General notes: There has been a change in the behavior of Emotet as reported earlier by the community(@dvk01uk, @pollo290987, etc). Emotet is now attaching a PDF document to each malspam message that is basically a plain text copy of the email itself. This is odd and I am not sure the point of it honestly. Other than this, it is the same old Emotet as far as I can tell. There are some slight changes in the body of the email posted below in examples.
  4.  
  5. Downloader links New for 03/01/18: (Integrated community links)
  6. from sandbox = found via SHA match or common payload
  7.  
  8. http://ailith-display.com/New-order/
  9. http://www.akzonobelspinaker.pl/Open-invoices/
  10. http://apteka.putemed.ru/ACH-form/
  11. http://bearit.ca/Paid-Invoices/
  12. http://begardi.com/Past-Due-Invoice/
  13. http://blog.followminehosting.com/Invoice-receipt/
  14. http://brightcore.biz/Scan/
  15. http://calhellas.net/ACH/GMO596200RQP/Mar-01-2018-3837560/IBT-YVBG-Mar-01-2018/ - from @Mesiagh
  16. http://cent-rdc.com/LLC/WAG9881560YFVWDR/Mar-01-2018-50051320/TTK-JLJ-Mar-01-2018/ - from @pollo290987 and @Mesiagh
  17. http://condosiesta.com/New-order/
  18. http://dhammaransi.com/ACH/XL7210504737YGJOS/Mar-01-2018-7121979345/XVYZ-PNL/
  19. http://fashion-tver.ru/Paid-Invoices/ - From @Mesiagh
  20. http://floristgo.ru/PAYMENT/ANW805869622SXBXGK/95586182/WOZL-HGUR/ - From @Mesiagh
  21. http://igold.capital/Inv-823132-PO-9W331881/ - From @Mesiagh
  22. http://www.lcjp.org/Service-Report-4137/
  23. http://loxtonfamily.info/Past-Due-Invoices/
  24. http://mastercoffeee.ru/Invoice-7545322-March/ - From @Mesiagh
  25. http://meridian-web.ru/Invoice-receipt/ - From @Mesiagh
  26. http://metaico.net/Important-Please-Read/ - From @Mesiagh
  27. http://mixincorps.com/Summit-Companies-Invoice-4307815/
  28. http://pruebas.rentserviceinformatica.com/New-order/ - from @dvk01uk
  29. http://rf-electric.com/Sales-Invoice/
  30. http://teamsites.ru/Service-Report-1722/ - From @Mesiagh
  31. http://top-prodazha.ru/INFO/FR073308721ZK/954074/TX-OQYSV/ - From @Mesiagh
  32. https://udare-shop.com/Past-Due-Invoices/
  33. http://xn----7sbbha3arb1f6dp.xn--p1ai/Invoice-2911560/
  34.  
  35. New Payloads seen today 03/01/18: (also seen by @HAMESWT_MHT, @pollo290987, @NelsonSecurity
  36. http://www.abexport.com/1ZQqbk/ - 62.149.140.190
  37. http://try-o.ru/dDC9Eo/dDC9Eo/ - 31.184.194.115
  38. http://nbzip.ru/CDvxeez/ - 88.212.247.52 (seen before with downloader)
  39. http://www.irasetaranto.it/tymS4SC/ - 89.46.106.56
  40. http://test.itsdco.com/gPzhcDB/ - 46.34.160.34
  41.  
  42. New Payloads from Community:
  43. https://pastebin.com/X0nJttmK - from @NelsonSecurity
  44.  
  45. kelvinboerkamp.nl/SuE3cCp/ - 141.138.169.218 - from @JAMESWT_MHT, @NelsonSecurity, @Fumik0_
  46. stagingnadra.online/gpr6rbq - 209.182.196.25 - from @JAMESWT_MHT, @NelsonSecurity, @Fumik0_
  47. reinider.ru/OtLkRU/ - 194.67.196.104 - from @JAMESWT_MHT, @NelsonSecurity, @Fumik0_
  48. arkonziv.com/Site7_Pixelhobbies/iV1PKqL/ - 182.50.135.128 - from @JAMESWT_MHT, @NelsonSecurity, @Fumik0_
  49. jlatreasures.com/DETbz/ - 184.106.55.108 - from @JAMESWT_MHT, @NelsonSecurity, @Fumik0_
  50.  
  51. C2:
  52. 106.187.91.235
  53. 45.56.65.180
  54. 91.217.66.130
  55. 119.59.124.163 - From @Mesiagh
  56.  
  57. Sandbox:
  58. https://app.any.run/tasks/8c57345a-6901-46fb-9162-6555dac15047 - with fakenet
  59. https://www.hybrid-analysis.com/sample/f295640889927e8709a3a2b8ee9df4442197eda568c7270a66607e4583c6d4ee?environmentId=100
  60. https://app.any.run/tasks/f2700ccc-7b6c-4915-af24-7ab6e9b61a12 - with fakenet - from @JAMESWT_MHT
  61.  
  62.  
  63. Additional Info from Community:
  64.  
  65. https://pastebin.com/h0tdAxNV - Hash and network from @Artillerie
  66. https://pastebin.com/UU9L2w78 - more downloader urls and payloads From @Mesiagh
  67. https://twitter.com/CapeSandbox/status/969268365318610944
  68. https://twitter.com/malware_traffic/status/969275762653192193
  69. https://twitter.com/fumik0_/status/969298743496445952
  70. https://pastebin.com/VrtFAGjP - from @_ddoxer
  71.  
  72. Samples of PDF body:
  73.  
  74. Morning {RCPT.NAME}
  75. Thanks Your invoice is attached. Please remit payment at your earliest
  76. convenience. Thank you for your business - we appreciate it very much.
  77. > http://www.akzonobelspinaker.pl/Open-invoices/
  78. {FRIEND.EMAIL}
  79. {FRIEND.NAME}
  80.  
  81. was attached in email with body:
  82.  
  83. Morning (Victim)
  84.  
  85.  
  86.  
  87. Thanks
  88. Your invoice is attached. Please remit payment at your earliest convenience.
  89. Thank you for your business - we appreciate it very much.
  90.  
  91. > http://www.akzonobelspinaker.pl/Open-invoices/
  92.  
  93.  
  94.  
  95.  
  96.  
  97. (Spoofed)
  98.  
  99.  
  100.  
  101. Scan of above PDF:
  102.  
  103. https://www.virustotal.com/#/file/9616629c1109beabb4491a525e7f1ea4441bbbea7867eb8f941073a6012402de/detection
  104.  
  105. Another copy of a sample PDF from @DynamicAnalysis:
  106. https://twitter.com/DynamicAnalysis/status/969351220841402368
  107.  
  108. Examples of body changes:
  109. note: seeing more HTML ones now.
  110.  
  111. Example #1
  112. Hi (Victim),
  113.  
  114.  
  115.  
  116. Inserted are the three invoices that need to be corrected. The correct rates are as follows:
  117. Regular Pay Rate: $25.21
  118. Regular Bill Rate: $67.53
  119. OT Pay Rate: $23.18
  120. OT Bill Rate: $36.61
  121. Please do not hesitate to contact me if you have any questions. Thanks!
  122.  
  123. >>> http://www.akzonobelspinaker.pl/Open-invoices/
  124.  
  125.  
  126.  
  127.  
  128.  
  129. (Spoofed)
  130. Información Confidencial: La información contenida en este correo electrónico y cualquier anexo del mismo puede contener información Confidencial para uso exclusivo de su destinatario. Si usted no es el destinatario de este correo electrónico favor de notificar al remitente respondiendo al presente correo y proceder a su destrucción inmediata, incluyendo los anexos y cualquier copia del mismo. El presente correo electrónico no constituye una oferta vinculante para la empresa, aun si el precio(s), cantidad(es) u otros conceptos similares son incluidos en el mensaje electrónico o en sus archivos adjuntos. Aviso de Privacidad: Sus datos personales pueden ser tratados para diferentes finalidades con motivo de la relación que mantengamos con Usted. Si requiere mayor información puede acceder al Aviso de Privacidad a través de la página de internet www.grupoabx.com.mx
  131.  
  132. Example #2
  133. <html>
  134. <body>
  135. (Victim)
  136. <br>
  137. <br>
  138.  
  139. I sent an email on 03/01/2018 and never got a response. We are now showing six past due invoices. Inserted is a current aging.
  140. I would appreciate it if you could check on it and let me know when we can expect payment. Thanks!
  141. <br>
  142. <br>
  143. >> <a href="http://mastercoffeee.ru/Invoice-7545322-March/">Open Past Due Orders.doc</a> (Attachment File Type: DOC)
  144. <br>
  145. <br>
  146. <br>
  147. <br>
  148.  
  149. Many Thanks<br>
  150. <br>
  151. (Spoofed)
  152. </body>
  153. </html>
  154.  
  155.  
  156. Bonus Content Additional URL Patterns: *WIP*
  157. (these may or may not work for you, use at your own risk. In my system(Vircom-Modusgate) they just put things into a quarantine and do not lose mail based on these filters.)
  158. ? = one character or space
  159. *=many characters or spaces
  160.  
  161. Merged old and new list together. Minor tweaks in lists:
  162.  
  163. Contains exact string type (In sieve script this is done via "if body:text:contains"):
  164.  
  165. ".com/UPS.com/",
  166. "/ACH-form/",
  167. "/Christmas-card/",
  168. "/Christmas-eCard/",
  169. "/Christmas-Gift-Card/",
  170. "/Corporation/New-invoice-",
  171. "/DOC/Invoice/",
  172. "/DOC/New-invoice-",
  173. "/document.jar",
  174. "/Document-needed/",
  175. "/Dokumente/",
  176. "/Dokumente-vom-Notar/",
  177. "/Download/Invoice-number-",
  178. "/eCard/",
  179. "/eGift-Card/",
  180. "/Final-Account/",
  181. "/Gift-Card-for-you",
  182. "/Happy-Holidays-Card/",
  183. "/Holidays-Card/",
  184. "/Holidays-eCard/",
  185. "/Holidays-gift-card/",
  186. "/Important-Please-Read/",
  187. "/INCORRECT-INVOICE/",
  188. "/INFO/Invoice-number-",
  189. "/Informationen/",
  190. "/Invoice-",
  191. "/Invoice-Corrections-for-",
  192. "/Invoice-for-t/",
  193. "/Invoice-for-you/",
  194. "/Invoice-Number-",
  195. "/Invoice-receipt/",
  196. "/Invoices-attached/",
  197. "/Invoices-Overdue/",
  198. "/Invoice-t/h-February/",
  199. "/LLC/New-invoice-/",
  200. "/Open-invoices/",
  201. "/Need-to-send-the-attachment/",
  202. "/New-order/",
  203. "/Open-Past-Due-Orders/",
  204. "/Order-Confirmation/",
  205. "/outstanding-invoice-",
  206. "/Outstanding-Invoices/",
  207. "/Overdue-payment/",
  208. "/Paid-Invoice/",
  209. "/Paid-Invoices/",
  210. "/Paid-Invoice-Credit-Card-Receipt/",
  211. "/Past-Due-Invoice",
  212. "-Past-Due-Invoices/",
  213. "/PayPal.com/LLC/",
  214. "/PAYPAL/DOC/",
  215. "/PAYPAL/INFO/",
  216. "/PayPal/LLC/",
  217. "/PayPal-US/DOC/",
  218. "/Purchases-2017/",
  219. "/Purchases-2018/",
  220. "/Question/",
  221. "/Rechnung/",
  222. "/Rechnung-Nr-",
  223. "/Rechnungs-Details/",
  224. "/scan/Invoice/",
  225. "/Sales-Invoice/",
  226. "/Service-Invoice/",
  227. "/Service-Report-",
  228. "/Summit-Companies-Invoice-",
  229. "/Tracking-Number-",
  230. "/UPS/Feb-",
  231. "/UPS-Express-Domestic/",
  232. "/UPS-Quantum-View/",
  233. "/UPS-Ship-Notification/",
  234. "/UPS-View/",
  235. "/wp-content/Invoice-Number-",
  236. "/Your-Card/",
  237. "/Your-Christmas-Card/",
  238. "/Your-Christmas-Gift-Card/",
  239. "/Your-eCard/",
  240. "/Your-Gift-Card/",
  241. "/Your-Holidays-Card/",
  242. "/Your-Holidays-eCard/",
  243. "/Your-holidays-Gift-Card/"
  244.  
  245.  
  246. Pattern match(done via if body:text:matches in Sieve script)
  247. "*http:/*.ru/ACH/*"
  248. "*http:/*/ACH/*-???-??-2018/ *"
  249. "*http:/*/ACH/*/???-??-2018-*"
  250. "*http:/*.info/CARD/*"
  251. "*http:/*/CARD/*-???-??-2018/ *"
  252. "*http:/*/CARD/*/???-??-2018-*"
  253. "*http:/*/Corporation/*-???-??-2018/ *"
  254. "*http:/*/Corporation/*/???-??-2018-*"
  255. "*http:/*.au/DOC/*"
  256. "*http:/*/DOC/*-???-??-2018/ *"
  257. "*http:/*/DOC/*/???-??-2018-*"
  258. "*http:/*/Download/*-???-??-2018/ *"
  259. "*http:/*/Download/*/???-??-2018-*"
  260. "*http:/*.sg/FILE/*"
  261. "*http:/*/FILE/*-???-??-2018/ *"
  262. "*http:/*/FILE/*/???-??-2018-*"
  263. "*http:/*.com/INFO/*"
  264. "*http:/*/INFO/*-???-??-2018/ *"
  265. "*http:/*/INFO/*/???-??-2018-*"
  266. "*http:/*.ru/LLC/*"
  267. "*http:/*/LLC/*-???-??-2018/ *"
  268. "*http:/*/LLC/*/???-??-2018-*"
  269. "*http:/*/PAY/*-???-??-2018/ *"
  270. "*http:/*/PAY/*/???-??-2018-*"
  271. "*http:/*/PAYMENT/*-???-??-2018/ *"
  272. "*http:/*/PAYMENT/*/???-??-2018-*"
  273. "*http:/*/Scan/ *"
  274. "*http:/*.com/Invoice/ *"
  275. "*http:/*.org/Invoice/ *"
  276. "*http:/*.pl/Invoice/ *"
  277. "*http:/*.ru/Invoice/ *"
  278. "*http:/*.su/Invoice/ *"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement