Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #2020-03-13_Japanese-reply-chain-mail-with-ursnif
- [maldoc sample]
- info_03_13.doc
- 03c815f9bfa9075772d7999072afd832
- https://app.any.run/tasks/a8c4625c-e745-48e0-984a-2be782514538/
- 2a489114b3fe3ce082f8e5dfa2065817
- https://app.any.run/tasks/e469daeb-41fd-4e31-8685-21870929cd13/
- #downloader
- [Payload URL]
- hxxp://netfletdriold[.]com/f64bj/jtrhs.php?l=ghsX.cab
- hxxp://netretgidare[.]com/f64bj/jtrhs.php?l=ghsX.cab
- # X : 1-3
- [Payload sample]
- 12345.dll
- 4fb50ab9a84f1720f1ca173386f9338d
- https://app.any.run/tasks/dd3ee6ee-b378-425d-b22d-751ff332010e/
- # malware: ursnif/Dreambot
- # export: DllRegisterServer
- # geofenced: jp (only JP geolocation can access)
- [C2]
- hxxp://get.marquettburton[.]com
- hxxp://alistherdata[.]at
- hxxp://h33a7jzovxp2dxfg[.]onion
- [URL QueryParameter]
- key=s4Sc9mDb35Ayj8oO
- soft=1
- version=217107
- server=12
- id=20203
- [Config Info]
- 0x1c631f09 :
- c2_domain : hxxp://h33a7jzovxp2dxfg[.]onion hxxp://get.marquettburton[.]com hxxp://alistherdata[.]at
- dga_base_url : constitution.org/usdeclar.txt
- 0xcd850e68 : 0x4eb7d2ca
- dga_tld : com ru org
- 0xdf2e7488 : 10
- tor32_dll : google.com file://%appdata%/system32.dll
- tor64_dll : google.com file://%appdata%/system64.dll
- ip_check_url : curlmyip.net
- server : 12
- serpent_key : s4Sc9mDb35Ayj8oO
- sleep_time : 10
- SetWaitableTimer_value(CRC_CONFIGTIMEOUT): 150
- time_value : 30
- SetWaitableTimer_value(CRC_TASKTIMEOUT): 150
- SetWaitableTimer_value(CRC_SENDTIMEOUT): 300
- SetWaitableTimer_value(CRC_KNOCKERTIMEOUT): 150
- not_use(CRC_BCTIMEOUT): 10
- botnet : 20203
- dga_seed : 1
- SetWaitableTimer_value: 60
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement