Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ANALYST NOTES
- Today I saw slightly lower Emotet volume.
- I had 64 recipients and, yet, I only got 8 Word document file hashes and 2 .exe hashes.
- As has been the case, I saw both "re-used" email threads and new stand-alone emails today.
- Some researchers said that they saw the use of Wscript today (with a .jse file) instead of Powershell.
- I did not - I continued to see Powershell in all cases.
- The Emotet VBA macros that I saw continue to generate simple base64 with no other obfuscation to be executed by Powershell.
- Like yesterday, CyberChef decodes the base64 and splits out the URLs with this recipe:
- From_Base64('A-Za-z0-9+/=',true)
- Decode_text('UTF16LE (1200)')
- Split('@','\\n')
- Extract_URLs(false)
- (it does leave a single quote artifact at the very end)
- SENDERS OBSERVED
- administracio@santmoritz.com
- administracion.agv@grupozoom.com
- aiza.vercide@airyougotravels.com
- andrew@corcoranengineers.ie
- arecvble@pacificfoam.com.pg
- bakery@alafiyagroup.com
- bea@trofeosmartinez.com
- bintulu_service2@dailieng.com.my
- bnp@supremegroup.com.my
- bochieng@trackntrace.co.ke
- celest.tan@kde.my
- csylvester@townofcarmel.org
- danvinmotors@telkomsa.net
- dcemdesk@powerlinksworld.com
- dee.alin@transfame.com.my
- docx@gtc.com.pk
- ejecutivo.senior@productoslavictoria.com.co
- erin@wisefoundation.com
- facturacion@ingerack.com
- faidzyal.hassan@transfame.com.my
- faltas.avarias@grupochibatao.com.br
- fandvops@freshtrade.co.zw
- fomondi@trackntrace.co.ke
- fortiz@expertosenaddendas.com
- george@skybluerestorations.com
- info@carrara-marble.com.au
- info@flextonrealties.com
- info@thecromwellcourtyardhotel.com
- info@trofeosmartinez.com
- jamal@carrara-marble.com.au
- josep@cutspain.com
- lasanadas@lasanadas.es
- layla.haji@hahco.net
- leadreturn@reutersproemail.com
- m.mroz@elzat.pl
- maria@kitchenpro.com.ph
- maria@rameshtrading.com.ph
- mrmolina@labomega.com.ar
- mskcgo@hermandad.com.tw
- mtaylor@highresolution.tv
- nathan@dispatchtcm.com
- noorulain@consult-tech.org
- nurul.syafiqah@permintex.com.my
- p.nowak@nordstrandperle.de
- pandiraj@sailssp.in
- praveen@thinksmartinfo.com
- quinform@quinform.com.my
- sales@niss.in
- sara.ahmad@connecme.com
- shoaib@sigmatech.pk
- supervisorarchivoccs@grupozoom.com
- Support.payroll@sinewave.co.in
- support015@datacontrol-ltd.com
- technical@sqrisksa.co.za
- traveldocs@myayg.com
- ventas@trofeosmartinez.com
- wally@carrara-marble.com.au
- woredo@trackntrace.co.ke
- yen@evantek.com
- yousef@istlight.com
- zainul@hzncars.com.my
- WORD DOCUMENT FILE HASHES
- 4a48396815ffca9806cb8d10db52ad25
- 4f78611ee813a5abdfbe3c2e6841350a
- 50e042d7afe697f829e0a5a78a0707b8
- 92509b1b9f0114433c4ddd758d5dcb82
- a44247cf3f3b4bedd6c1eb123fd973d1
- a7833773b84ccb6fd797db9f510bf843
- a9b55918ff86759869163a91ffc4b700
- f0c2eca72f75cfbf13e56ddba5d99767
- PAYLOAD FILE HASHES
- cdf8eafed40b73a32202e63427c30489
- dd1b03b522af0990bee0c4bc8ba81aab
- EMOTET PAYLOAD URLs
- http://altaikawater.com/wp-admin/4jh8s_sxm6m3eec-441/
- http://antoinegimenez.com/css/hUgHbaEf/
- http://aplikasi.bangunrumah-kita.com/b8kee0mj/0m3l_clo7kkcub-76/
- http://auto-moto-ecole-vauban.fr/wp-admin/ww42_lwln3c-1236328628/
- http://avant2017.amsi-formations.com/prog/skzHGQddV/
- http://cheaptrainticket.cogbiz-infotech.com/cgi-bin/9vsx4g6l_p5x29co-43731795/
- http://fabiogutierrez.com.br/loja/bEZYtLkJGj/
- http://gruasasuservicio.com/cgi-bin/YdFmLIEsIB/
- http://gsfcloud.com/fir/qx88b0qgfq_tdpfmobexf-881829012/
- http://itf.palemiya.com/wp-includes/IIswblOCV/
- http://moda.9l.pl/calendar/HugncgqxUR/
- http://precisieving.com/wp-admin/db090yl5_bwwmv-86392/
- http://sweetmagazine.org/wp-admin/z0jxuhjao_n6me674y8i-3862/
- http://ucomechina.com/wp-content/aVMBsBCy/
- http://your-event.es/mailin/OgXcBNiq/
- EMOTET C2s
- http://88.156.97.210
- http://199.19.237.192
- http://190.108.228.48:990
- http://212.129.24.82:8080
- http://162.144.47.94:7080
- http://77.237.248.136:8080
- http://185.142.236.163:443
- http://63.142.253.122:8080
- http://78.24.219.147:8080
- http://200.21.90.6
- http://85.104.59.244:20
- http://86.98.25.30:53
- http://222.214.218.192:8080
- http://5.196.74.210:8080
- http://31.12.67.62:7080
- http://190.145.67.134:8090
- http://178.79.161.166:443
- http://104.131.11.150:8080
- http://101.187.237.217:20
- http://188.166.253.46:8080
- http://190.106.97.230:443
- http://185.94.252.13:443
- http://186.75.241.230
- http://103.255.150.84
- http://211.63.71.72:8080
- http://179.32.19.219:22
- http://31.172.240.91:8080
- http://45.123.3.54:443
- http://159.65.25.128:8080
- http://177.246.193.139:20
- http://182.176.106.43:995
- http://149.202.153.252:8080
- http://217.145.83.44
- http://46.105.131.87
- http://187.144.189.58:50000
- http://92.222.216.44:8080
- http://190.186.203.55
- http://88.247.163.44
- http://41.220.119.246
- http://37.157.194.134:443
- http://190.18.146.70
- http://206.189.98.125:8080
- http://85.106.1.166:50000
- http://80.11.163.139:443
- http://201.251.43.69:8080
- http://149.167.86.174:990
- http://87.230.19.21:8080
- http://200.71.148.138:8080
- http://142.44.162.209:8080
- http://169.239.182.217:8080
- http://138.201.140.110:8080
- http://92.222.125.16:7080
- http://189.209.217.49
- http://47.41.213.2:22
- http://87.106.136.232:8080
- http://190.211.207.11:443
- http://27.147.163.188:8080
- http://212.71.234.16:8080
- http://190.228.72.244:53
- http://62.75.187.192:8080
- http://186.4.172.5:443
- http://83.136.245.190:8080
- http://173.212.203.26:8080
- http://186.4.172.5:8080
- http://94.205.247.10
- http://91.205.215.66:8080
- http://144.139.247.220
- http://87.106.139.101:8080
- http://119.15.153.237
- http://182.76.6.2:8080
- http://45.33.49.124:443
- http://182.176.132.213:8090
- http://136.243.177.26:8080
- http://104.236.246.93:8080
- http://181.143.194.138:443
- http://178.254.6.27:7080
- http://217.160.182.191:8080
- http://95.128.43.213:8080
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement