Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #smokeloader #signed #7z #exe
- https://pastebin.com/WYsm7Jyk
- previous_contact:
- https://pastebin.com/UfW73LSg
- https://pastebin.com/e46KzBWE
- https://pastebin.com/xEwN5JPc
- https://pastebin.com/GMwv38g4
- https://pastebin.com/DgFvarG0
- https://pastebin.com/AayUSaXq
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.smokeloader
- https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
- attack_vector
- --------------
- email attach .7z (PWD) > exe1 and exe2 > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Fri, 26 Jan 2024 08:41:23 +0000
- Subject: Fw: Рахунок (канц. товари)
- From: Компанiя Папiрус <jwilson@spmcotx_com>
- Received: from mail_dlkpc_com (47_190_39_223)
- Reply-To: "umaoda@meta_ua" <umaoda@meta_ua>
- Message-ID: <wri6p0i-zambac-06@spmcotx_com>
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 297d5a2231d9dedf998db29e402cd71dd775eba3073b50f7cca0d21f0365bb2d
- File name Рахунок_ПУ19_10958_та_Договiр_11224.7z [7-zip archive, v 0.4] !PWD
- File size 176.66 KB (180896 bytes)
- SHA-256 4841be428d00d29ab878fda23850d948bc2d12eefb31621c0272e301d95bbc7f
- File name ДОГОВIР_ПОСТАВКА_11224_Вiд_12_01_2024p.PDF.exe [PE32 executable] !Smokeloader
- File size 344.59 KB (352864 bytes)
- SHA-256 6a684f04b6dc6ed0ca2bc55dec214e78c664aa18ee412fd290e6d543866115a9
- File name Ранунок_фактура_вiд_23_01_2024р_UA35...PDF.exe [PE32 executable] !Smokeloader
- File size 344.59 KB (352864 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR email_attach
- C2 kitfishstore_ru /index.php
- homemademagazine_ru /index.php
- netwrk
- --------------
- n/a
- comp
- --------------
- n/a
- proc
- --------------
- C:\Users\operator\Desktop\ДОГОВIР_ПОСТАВКА_11224_Вiд_12_01_2024p.PDF.exe
- persist
- --------------
- n/a
- drop
- --------------
- n/a
- # # # # # # # #
- additional info
- # # # # # # # #
- {
- "Version": 2022,
- "C2 list":
- kitfishstore_ru /index.php,
- homemademagazine_ru /index.php
- }
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/297d5a2231d9dedf998db29e402cd71dd775eba3073b50f7cca0d21f0365bb2d/details
- https://www.virustotal.com/gui/file/4841be428d00d29ab878fda23850d948bc2d12eefb31621c0272e301d95bbc7f/details
- https://www.virustotal.com/gui/file/6a684f04b6dc6ed0ca2bc55dec214e78c664aa18ee412fd290e6d543866115a9/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement