Advertisement
ExecuteMalware

2019-09-26 Emotet IOCs

Sep 26th, 2019
8,570
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.60 KB | None | 0 0
  1. ANALYST NOTES
  2. Today I saw slightly lower Emotet volume.
  3. I had 64 recipients and, yet, I only got 8 Word document file hashes and 2 .exe hashes.
  4. As has been the case, I saw both "re-used" email threads and new stand-alone emails today.
  5. Some researchers said that they saw the use of Wscript today (with a .jse file) instead of Powershell.
  6. I did not - I continued to see Powershell in all cases.
  7. The Emotet VBA macros that I saw continue to generate simple base64 with no other obfuscation to be executed by Powershell.
  8.  
  9. Like yesterday, CyberChef decodes the base64 and splits out the URLs with this recipe:
  10. From_Base64('A-Za-z0-9+/=',true)
  11. Decode_text('UTF16LE (1200)')
  12. Split('@','\\n')
  13. Extract_URLs(false)
  14.  
  15. (it does leave a single quote artifact at the very end)
  16.  
  17. SENDERS OBSERVED
  18.  
  19.  
  20. WORD DOCUMENT FILE HASHES
  21. 4a48396815ffca9806cb8d10db52ad25
  22. 4f78611ee813a5abdfbe3c2e6841350a
  23. 50e042d7afe697f829e0a5a78a0707b8
  24. 92509b1b9f0114433c4ddd758d5dcb82
  25. a44247cf3f3b4bedd6c1eb123fd973d1
  26. a7833773b84ccb6fd797db9f510bf843
  27. a9b55918ff86759869163a91ffc4b700
  28. f0c2eca72f75cfbf13e56ddba5d99767
  29.  
  30. PAYLOAD FILE HASHES
  31. cdf8eafed40b73a32202e63427c30489
  32. dd1b03b522af0990bee0c4bc8ba81aab
  33.  
  34. EMOTET PAYLOAD URLs
  35. http://altaikawater.com/wp-admin/4jh8s_sxm6m3eec-441/
  36. http://antoinegimenez.com/css/hUgHbaEf/
  37. http://aplikasi.bangunrumah-kita.com/b8kee0mj/0m3l_clo7kkcub-76/
  38. http://auto-moto-ecole-vauban.fr/wp-admin/ww42_lwln3c-1236328628/
  39. http://avant2017.amsi-formations.com/prog/skzHGQddV/
  40. http://cheaptrainticket.cogbiz-infotech.com/cgi-bin/9vsx4g6l_p5x29co-43731795/
  41. http://fabiogutierrez.com.br/loja/bEZYtLkJGj/
  42. http://gruasasuservicio.com/cgi-bin/YdFmLIEsIB/
  43. http://gsfcloud.com/fir/qx88b0qgfq_tdpfmobexf-881829012/
  44. http://itf.palemiya.com/wp-includes/IIswblOCV/
  45. http://moda.9l.pl/calendar/HugncgqxUR/
  46. http://precisieving.com/wp-admin/db090yl5_bwwmv-86392/
  47. http://sweetmagazine.org/wp-admin/z0jxuhjao_n6me674y8i-3862/
  48. http://ucomechina.com/wp-content/aVMBsBCy/
  49. http://your-event.es/mailin/OgXcBNiq/
  50.  
  51. EMOTET C2s
  52. http://88.156.97.210
  53. http://199.19.237.192
  54. http://190.108.228.48:990
  55. http://212.129.24.82:8080
  56. http://162.144.47.94:7080
  57. http://77.237.248.136:8080
  58. http://185.142.236.163:443
  59. http://63.142.253.122:8080
  60. http://78.24.219.147:8080
  61. http://200.21.90.6
  62. http://85.104.59.244:20
  63. http://86.98.25.30:53
  64. http://222.214.218.192:8080
  65. http://5.196.74.210:8080
  66. http://31.12.67.62:7080
  67. http://190.145.67.134:8090
  68. http://178.79.161.166:443
  69. http://104.131.11.150:8080
  70. http://101.187.237.217:20
  71. http://188.166.253.46:8080
  72. http://190.106.97.230:443
  73. http://185.94.252.13:443
  74. http://186.75.241.230
  75. http://103.255.150.84
  76. http://211.63.71.72:8080
  77. http://179.32.19.219:22
  78. http://31.172.240.91:8080
  79. http://45.123.3.54:443
  80. http://159.65.25.128:8080
  81. http://177.246.193.139:20
  82. http://182.176.106.43:995
  83. http://149.202.153.252:8080
  84. http://217.145.83.44
  85. http://46.105.131.87
  86. http://187.144.189.58:50000
  87. http://92.222.216.44:8080
  88. http://190.186.203.55
  89. http://88.247.163.44
  90. http://41.220.119.246
  91. http://37.157.194.134:443
  92. http://190.18.146.70
  93. http://206.189.98.125:8080
  94. http://85.106.1.166:50000
  95. http://80.11.163.139:443
  96. http://201.251.43.69:8080
  97. http://149.167.86.174:990
  98. http://87.230.19.21:8080
  99. http://200.71.148.138:8080
  100. http://142.44.162.209:8080
  101. http://169.239.182.217:8080
  102. http://138.201.140.110:8080
  103. http://92.222.125.16:7080
  104. http://189.209.217.49
  105. http://47.41.213.2:22
  106. http://87.106.136.232:8080
  107. http://190.211.207.11:443
  108. http://27.147.163.188:8080
  109. http://212.71.234.16:8080
  110. http://190.228.72.244:53
  111. http://62.75.187.192:8080
  112. http://186.4.172.5:443
  113. http://83.136.245.190:8080
  114. http://173.212.203.26:8080
  115. http://186.4.172.5:8080
  116. http://94.205.247.10
  117. http://91.205.215.66:8080
  118. http://144.139.247.220
  119. http://87.106.139.101:8080
  120. http://119.15.153.237
  121. http://182.76.6.2:8080
  122. http://45.33.49.124:443
  123. http://182.176.132.213:8090
  124. http://136.243.177.26:8080
  125. http://104.236.246.93:8080
  126. http://181.143.194.138:443
  127. http://178.254.6.27:7080
  128. http://217.160.182.191:8080
  129. http://95.128.43.213:8080
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement