VRad

#icedID_140422

Apr 15th, 2022 (edited)
389
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.46 KB | None | 0 0
  1. #IOC #OptiData #VR #icedID #BokBot #DLL #Macro #VBA
  2.  
  3. https://pastebin.com/X4EvL8N6
  4.  
  5. previous_contact:
  6. 23/03/2022 https://pastebin.com/LaxLgeEz
  7.  
  8. FAQ:
  9. https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid
  10.  
  11. attack_vector
  12. --------------
  13. email > XLS > VBA > GET 66.150.66.167/su.dll > rundll32.exe C:\Windows\Tasks\su.dll, PluginInit > ertimadifa.com
  14.  
  15.  
  16. # # # # # # # #
  17. email_headers
  18. # # # # # # # #
  19.  
  20. Subject: Мобилизационный список Указом Президента про термінову мобілізацію
  21. Received: from tiger.cfi.lu.lv (tiger.cfi.lu.lv [5.179.5.2])
  22. X-Virus-Scanned: amavisd-new at cfi.lu.lv
  23. Received: from webmail.cfi.lu.lv (tiger.cfi.lu.lv [IPv6:2001:67c:2198:44::2]) (Authenticated sender: ievalr) by tiger.cfi.lu.lv (Postfix) with ESMTPSA id 8AC2EC30448;
  24. From: Ieva Lācenberga-Rocēna <[email protected]>
  25. Date: Thu, 14 Apr 2022 19:38:03 +0000
  26. Message-ID: <[email protected]>
  27.  
  28.  
  29. # # # # # # # #
  30. files
  31. # # # # # # # #
  32.  
  33. SHA-256 08d30d6646117cd96320447042fb3857b4f82d80a92f31ee91b16044b87929c0
  34. File name Мобілізаційний список.xls [ Microsoft Excel sheet ]
  35. File size 32.50 KB (33280 bytes)
  36.  
  37. SHA-256 55df2954add86715fc3d728459d79a6d2b88d34d9f23fafe9c5a573bb773d9e9
  38. File name su.dll [ Win32 DLL , PE32+ executable for MS Windows (DLL) (GUI) Mono/.Net assembly ]
  39. File size 150.50 KB (154112 bytes)
  40.  
  41. SHA-256 548f11606b71fbc6f5fabb02003ecc600e282352b30f65fbce9c4ed52a044757
  42. File name Qoalodpf3.dll [ Win32 DLL , PE32+ executable for MS Windows (DLL) (GUI) Mono/.Net assembly ]
  43. File size 138.00 KB (141312 bytes)
  44.  
  45.  
  46. # # # # # # # #
  47. activity
  48. # # # # # # # #
  49.  
  50. PL_SCR http://66.150.66.167/su.dll
  51.  
  52. C2 ertimadifa.com 164.92.104.194
  53. rresteraftin.com 51.89.88.113
  54. detreville.top 45.142.214.176
  55. ndlestomak.top 51.89.88.113
  56.  
  57.  
  58. netwrk
  59. --------------
  60. 66.150.66.167 66.150.66.167 80 HTTP GET /su.dll HTTP/1.1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0)
  61. 164.92.104.194 ertimadifa.com 80 HTTP GET / HTTP/1.1
  62. 51.89.88.113 rresteraftin.com 443 TLSv1 Client Hello
  63. 45.142.214.176 detreville.top 443 TLSv1 Client Hello
  64. 51.89.88.113 ndlestomak.top 443 TLSv1 Client Hello
  65.  
  66.  
  67. comp
  68. --------------
  69. EXCEL.EXE 3500 TCP 66.150.66.167 80 ESTABLISHED
  70. rundll32.exe 3276 TCP 164.92.104.194 80 ESTABLISHED
  71. rundll32.exe 3276 TCP 51.89.88.113 443 ESTABLISHED
  72. rundll32.exe 3276 TCP 45.142.214.176 443 ESTABLISHED
  73.  
  74.  
  75. proc
  76. --------------
  77. "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" /e
  78. C:\Windows\SysWOW64\rundll32.exe C:\Windows\Tasks\su.dll, PluginInit
  79. C:\Windows\system32\rundll32.exe C:\Windows\Tasks\su.dll, PluginInit
  80.  
  81. persist
  82. --------------
  83. \nofecuunvi_{FEEAF16C-A218-784B-8F1A-9F7313AED5EA}
  84. c:\users\operator\appdata\local\{5f5ab27b-8b0f-a2dd-da8e-04c7f98cd02a}\qoalodpf3.dll 26.12.2015 11:47
  85. \nofecuunvi_{FEEAF16C-A218-784B-8F1A-9F7313AED5EA} c:\users\operator\appdata\local\{5f5ab27b-8b0f-a2dd-da8e-04c7f98cd02a}\qoalodpf3.dll 26.12.2015 11:47
  86.  
  87.  
  88. drop
  89. --------------
  90. C:\tmp\Temporary Internet Files\Content.IE5\9XH0ADWM\su[1].dll
  91. C:\Windows\Tasks\su.dll
  92. C:\Users\operator\AppData\Local\{5F5AB27B-8B0F-A2DD-DA8E-04C7F98CD02A}\Qoalodpf3.dll
  93.  
  94.  
  95. # # # # # # # #
  96. additional info
  97. # # # # # # # #
  98.  
  99. xls metadata
  100. --------------
  101. File Name : Мобілізаційний список.xls
  102. Directory : .
  103. File Size : 32 KiB
  104. File Modification Date/Time : 2022:04:15 10:08:43+03:00
  105. File Access Date/Time : 2022:04:15 16:18:56+03:00
  106. File Inode Change Date/Time : 2022:04:15 18:42:20+03:00
  107. File Permissions : -rw-rw-r--
  108. File Type : XLS
  109. File Type Extension : xls
  110. MIME Type : application/vnd.ms-excel
  111. Author :
  112. Software : Microsoft Excel
  113. Create Date : 2022:04:14 18:51:43
  114. Modify Date : 2022:04:14 18:51:43
  115. Security : None
  116. Code Page : Windows Cyrillic
  117. Company :
  118. App Version : 15.0000
  119. Scale Crop : No
  120. Links Up To Date : No
  121. Shared Doc : No
  122. Hyperlinks Changed : No
  123. Title Of Parts : Лист1
  124. Heading Pairs : Листы, 1
  125. Comp Obj User Type Len : 26
  126. Comp Obj User Type : ���� Microsoft Excel 2003
  127.  
  128.  
  129. # # # # # # # #
  130. VT & Intezer
  131. # # # # # # # #
  132.  
  133. Dropped files
  134. **************
  135. https://www.virustotal.com/gui/file/08d30d6646117cd96320447042fb3857b4f82d80a92f31ee91b16044b87929c0/details
  136. https://www.virustotal.com/gui/file/55df2954add86715fc3d728459d79a6d2b88d34d9f23fafe9c5a573bb773d9e9/details
  137. https://analyze.intezer.com/analyses/ec3a5660-0f3d-478b-8ac9-e6ff9f567946
  138. https://www.virustotal.com/gui/file/548f11606b71fbc6f5fabb02003ecc600e282352b30f65fbce9c4ed52a044757/details
  139. https://analyze.intezer.com/analyses/79c92ddf-cfc0-4875-a1ba-373f70f353c7
  140.  
  141. PL_SCR
  142. **************
  143. https://www.virustotal.com/gui/url/bf874a0c033677efaa3032ac45c4b1f4c7e357bc5c5c83371af71feb529d1ef7/details
  144.  
  145. C2
  146. **************
  147. https://www.virustotal.com/gui/domain/ertimadifa.com/details
  148.  
  149. VR
Add Comment
Please, Sign In to add comment