Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #remcos #SMB #RAT #mic #keylog #scr
- https://pastebin.com/aG6XyqHN
- previous_contact:
- 13/11/23 https://pastebin.com/tbRpiGG5
- 06/02/23 https://pastebin.com/kjv5E8Au
- 12/07/21 https://pastebin.com/ZYZarB9L
- 15/07/19 https://pastebin.com/ZxG6eRWM
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
- attack_vector
- --------------
- email > att1 .RAR > att2 .RAR (pwd) > .doc (vba) > SMB \\89_23_98_22\LN\scandoc.exe > ProgramData\Davinci\8161.exe > C2
- # # # # # # # #
- email_headers
- # # # # # # # #
- Subject: Повістка в суд-вихідний : 655559638577 від 30.11.2023
- Received: from mailgw1.court.gov.ua ([212.90.190.159])
- Message-Id: <202311300304.3AU34DRl015266-3AU34DRm015266@mailgw1.court.gov.ua>
- From: Господарський суд Одеської області <zal15@od.arbitr.gov.ua>
- Reply-To: <inbox@adm.od.court.gov.ua>
- Date: Thu, 30 Nov 2023 06:04:09 +0300
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 26b4ccad487e76f40a5806c638589d3b2fb29bd799accc1cfaa6739e7ec437df
- File name Господарський суд Одеської області Повістка до суду.rar [ RAR archive data, v5 ]
- File size 508.61 KB (520819 bytes)
- SHA-256 aa6de205e6d84c8333fd503c06fc27f55d67d04221a87481793b41070d76268f
- File name Повістка до суду.rar [ RAR archive data, v5 ] PWD!
- File size 507.75 KB (519934 bytes)
- SHA-256 a7aca87179f51e229aa9a2f13bb8ab76750c8092579cc7b4d0cbc40235cdde27
- File name Повістка до суду.doc [ Microsoft Word document ]
- File size 675.00 KB (691200 bytes)
- SHA-256 ff0a84220d028052a841312cd81baa525d19f7e4b0ce94dbbaf6634a776d3814
- File name scandoc.exe (8161.exe) [ .NET executable ]
- File size 11.87 MB (12443648 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR \\89_23_98_22 \ scandoc.exe
- C2 95_214_26_199 :} 80
- 95_214_26_199 :} 465
- netwrk
- --------------
- 178.237.33.50 geoplugin.net 80 HTTP GET /json.gp HTTP/1.1
- 89_23_98_22 445 SMB2 Tree Connect Request Tree: \\89_23_98_22\IPC$
- 89_23_98_22 445 SMB2 Create Request File: scandoc.exe
- 95_214_26_199 80 TCP 61412 → 80 [ACK] Seq=670 Ack=98572 Win=262400 Len=0
- comp
- --------------
- System TCP 89_23_98_22 445 ESTABLISHED
- 8161.exe TCP 95_214_26_199 80 ESTABLISHED
- proc
- --------------
- "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde
- C:\Windows\SysWOW64\explorer.exe "\\89_23_98_22\LN \"
- \??\UNC\89_23_98_22\LN\scandoc.exe
- C:\ProgramData\Davinci\8161.exe
- persist
- --------------
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 30.11.2023 15:16
- Dv8161-E2WPIJ 7-Zip Installer Igor Pavlov c:\programdata\davinci\8161.exe 29.11.2023 14:48
- drop
- --------------
- c:\programdata\davinci\8161.exe
- # # # # # # # #
- additional info
- # # # # # # # #
- malware_config
- {
- "Version": "4.9.3 Pro",
- "Host:Port:Password": "95_214_26_199 :} 80",
- "Assigned name": "RMC",
- "Connect interval": "1",
- "Install flag": "Enable",
- "Setup HKCU\\Run": "Enable",
- "Setup HKLM\\Run": "Enable",
- "Install path": "Application path",
- "Copy file": "8161.exe",
- "Startup value": "Disable",
- "Hide file": "Disable",
- "Mutex": "Dv8161-E2WPIJ",
- "Keylog flag": "0",
- "Keylog path": "Application path",
- "Keylog file": "logs.dat",
- "Keylog crypt": "Disable",
- "Hide keylog file": "Disable",
- "Screenshot flag": "Disable",
- "Screenshot time": "10",
- "Take Screenshot option": "Disable",
- "Take screenshot title": "",
- "Take screenshot time": "5",
- "Screenshot path": "AppData",
- "Screenshot file": "Screenshots",
- "Screenshot crypt": "Disable",
- "Mouse option": "Disable",
- "Delete file": "Disable",
- "Audio record time": "5"
- }
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/26b4ccad487e76f40a5806c638589d3b2fb29bd799accc1cfaa6739e7ec437df/details
- https://www.virustotal.com/gui/file/aa6de205e6d84c8333fd503c06fc27f55d67d04221a87481793b41070d76268f/details
- https://www.virustotal.com/gui/file/a7aca87179f51e229aa9a2f13bb8ab76750c8092579cc7b4d0cbc40235cdde27/details
- https://www.virustotal.com/gui/file/ff0a84220d028052a841312cd81baa525d19f7e4b0ce94dbbaf6634a776d3814/details
- https://analyze.intezer.com/analyses/f943ad68-84f5-4373-9c72-1d5ed9cfe56a
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement