Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #icedID #BokBot #DLL #Macro #VBA
- https://pastebin.com/X4EvL8N6
- previous_contact:
- 23/03/2022 https://pastebin.com/LaxLgeEz
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid
- attack_vector
- --------------
- email > XLS > VBA > GET 66.150.66.167/su.dll > rundll32.exe C:\Windows\Tasks\su.dll, PluginInit > ertimadifa.com
- # # # # # # # #
- email_headers
- # # # # # # # #
- Subject: Мобилизационный список Указом Президента про термінову мобілізацію
- Received: from tiger.cfi.lu.lv (tiger.cfi.lu.lv [5.179.5.2])
- X-Virus-Scanned: amavisd-new at cfi.lu.lv
- Received: from webmail.cfi.lu.lv (tiger.cfi.lu.lv [IPv6:2001:67c:2198:44::2]) (Authenticated sender: ievalr) by tiger.cfi.lu.lv (Postfix) with ESMTPSA id 8AC2EC30448;
- From: Ieva Lācenberga-Rocēna <ieva.lacenberga-rocena@cfi.lu.lv>
- Date: Thu, 14 Apr 2022 19:38:03 +0000
- Message-ID: <c06241db60aabf1f7ac815e69a0890d6@cfi.lu.lv>
- X-Sender: ieva.lacenberga-rocena@cfi.lu.lv
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 08d30d6646117cd96320447042fb3857b4f82d80a92f31ee91b16044b87929c0
- File name Мобілізаційний список.xls [ Microsoft Excel sheet ]
- File size 32.50 KB (33280 bytes)
- SHA-256 55df2954add86715fc3d728459d79a6d2b88d34d9f23fafe9c5a573bb773d9e9
- File name su.dll [ Win32 DLL , PE32+ executable for MS Windows (DLL) (GUI) Mono/.Net assembly ]
- File size 150.50 KB (154112 bytes)
- SHA-256 548f11606b71fbc6f5fabb02003ecc600e282352b30f65fbce9c4ed52a044757
- File name Qoalodpf3.dll [ Win32 DLL , PE32+ executable for MS Windows (DLL) (GUI) Mono/.Net assembly ]
- File size 138.00 KB (141312 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR http://66.150.66.167/su.dll
- C2 ertimadifa.com 164.92.104.194
- rresteraftin.com 51.89.88.113
- detreville.top 45.142.214.176
- ndlestomak.top 51.89.88.113
- netwrk
- --------------
- 66.150.66.167 66.150.66.167 80 HTTP GET /su.dll HTTP/1.1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0)
- 164.92.104.194 ertimadifa.com 80 HTTP GET / HTTP/1.1
- 51.89.88.113 rresteraftin.com 443 TLSv1 Client Hello
- 45.142.214.176 detreville.top 443 TLSv1 Client Hello
- 51.89.88.113 ndlestomak.top 443 TLSv1 Client Hello
- comp
- --------------
- EXCEL.EXE 3500 TCP 66.150.66.167 80 ESTABLISHED
- rundll32.exe 3276 TCP 164.92.104.194 80 ESTABLISHED
- rundll32.exe 3276 TCP 51.89.88.113 443 ESTABLISHED
- rundll32.exe 3276 TCP 45.142.214.176 443 ESTABLISHED
- proc
- --------------
- "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" /e
- C:\Windows\SysWOW64\rundll32.exe C:\Windows\Tasks\su.dll, PluginInit
- C:\Windows\system32\rundll32.exe C:\Windows\Tasks\su.dll, PluginInit
- persist
- --------------
- \nofecuunvi_{FEEAF16C-A218-784B-8F1A-9F7313AED5EA}
- c:\users\operator\appdata\local\{5f5ab27b-8b0f-a2dd-da8e-04c7f98cd02a}\qoalodpf3.dll 26.12.2015 11:47
- \nofecuunvi_{FEEAF16C-A218-784B-8F1A-9F7313AED5EA} c:\users\operator\appdata\local\{5f5ab27b-8b0f-a2dd-da8e-04c7f98cd02a}\qoalodpf3.dll 26.12.2015 11:47
- drop
- --------------
- C:\tmp\Temporary Internet Files\Content.IE5\9XH0ADWM\su[1].dll
- C:\Windows\Tasks\su.dll
- C:\Users\operator\AppData\Local\{5F5AB27B-8B0F-A2DD-DA8E-04C7F98CD02A}\Qoalodpf3.dll
- # # # # # # # #
- additional info
- # # # # # # # #
- xls metadata
- --------------
- File Name : Мобілізаційний список.xls
- Directory : .
- File Size : 32 KiB
- File Modification Date/Time : 2022:04:15 10:08:43+03:00
- File Access Date/Time : 2022:04:15 16:18:56+03:00
- File Inode Change Date/Time : 2022:04:15 18:42:20+03:00
- File Permissions : -rw-rw-r--
- File Type : XLS
- File Type Extension : xls
- MIME Type : application/vnd.ms-excel
- Author :
- Software : Microsoft Excel
- Create Date : 2022:04:14 18:51:43
- Modify Date : 2022:04:14 18:51:43
- Security : None
- Code Page : Windows Cyrillic
- Company :
- App Version : 15.0000
- Scale Crop : No
- Links Up To Date : No
- Shared Doc : No
- Hyperlinks Changed : No
- Title Of Parts : Лист1
- Heading Pairs : Листы, 1
- Comp Obj User Type Len : 26
- Comp Obj User Type : ���� Microsoft Excel 2003
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- Dropped files
- **************
- https://www.virustotal.com/gui/file/08d30d6646117cd96320447042fb3857b4f82d80a92f31ee91b16044b87929c0/details
- https://www.virustotal.com/gui/file/55df2954add86715fc3d728459d79a6d2b88d34d9f23fafe9c5a573bb773d9e9/details
- https://analyze.intezer.com/analyses/ec3a5660-0f3d-478b-8ac9-e6ff9f567946
- https://www.virustotal.com/gui/file/548f11606b71fbc6f5fabb02003ecc600e282352b30f65fbce9c4ed52a044757/details
- https://analyze.intezer.com/analyses/79c92ddf-cfc0-4875-a1ba-373f70f353c7
- PL_SCR
- **************
- https://www.virustotal.com/gui/url/bf874a0c033677efaa3032ac45c4b1f4c7e357bc5c5c83371af71feb529d1ef7/details
- C2
- **************
- https://www.virustotal.com/gui/domain/ertimadifa.com/details
- VR
Add Comment
Please, Sign In to add comment