VRad

#nanocore_250419

May 10th, 2019
1,267
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.20 KB | None | 0 0
  1. #IOC #OptiData #VR #nanocore #RAT #RTF #OLE #XLS #VBA
  2.  
  3. https://pastebin.com/cSy68j5q
  4.  
  5. previous_contact:
  6. 07/01/19 https://pastebin.com/e5f24Y8F
  7.  
  8. FAQ: https://krebsonsecurity.com/2018/02/bot-roundup-avalanche-kronos-nanocore/
  9.  
  10. attack_vector
  11. --------------
  12. email attach .doc (RTF) > OLE > 2 excel > macro_URLDownloadToFileA > GET 1 URL > .exe
  13.  
  14. email_headers
  15. --------------
  16. Received: from bitrecall.com (mail.bitrecall.com [94.177.166.132])
  17. Received: from pec.it (unknown [184.164.139.195])
  18. From: Accounts <[email protected]>
  19. Subject: Re: Invoice payment
  20. Date: 25 Apr 2019 05:18:16 -0700
  21.  
  22. files
  23. --------------
  24. SHA-256 6be4c966edc63f37f52fc3a935344f634a8bb064d97200a31c0a3d2459ceda26
  25. File name invoice and po.doc [Rich Text Format data, version 1, unknown character set]
  26. File size 290.43 KB (297400 bytes)
  27.  
  28. two OLE from RTF:
  29.  
  30. SHA-256 0637afed4d69d13579b0f046e8897d4559fd0c3a4d77be16e8d00b23f6c38500
  31. File name invoice and po.doc_object_00002904.bin [Composite Document File V2 Document, Little Endian, Os: Windows]
  32. File size 51 KB (52224 bytes)
  33.  
  34. SHA-256 17abc93230013c514555b8c99fdc359aa73427d47b409d643dc2c6a7d20d8961
  35. File name invoice and po.doc_object_00021CCF.bin [Composite Document File V2 Document, Little Endian, Os: Windows]
  36. File size 51 KB (52224 bytes)
  37.  
  38. payload:
  39.  
  40. SHA-256 56f4a8947d55e20bc17f7e05dcc7484940c19845366c3e22ffa4f02e7cffd1cb
  41. File name stub[1].exe [PE32 executable (GUI) Intel 80386, for MS Windows]
  42. File size 521.87 KB (534392 bytes)
  43.  
  44. activity
  45. **************
  46.  
  47. PL_SRC 104.238.117.30 depedpasay{.} ph [ssl]
  48.  
  49. C2 91.192.100.11 [ssl]
  50.  
  51. netwrk
  52. --------------
  53. 104.238.117.30 depedpasay{.} ph Client Hello
  54. 91.192.100.11 49188 → 7077 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
  55.  
  56. comp
  57. --------------
  58. EXCEL.EXE 220 TCP localhost 49185 104.238.117.30 443 ESTABLISHED
  59. EXCEL.EXE 220 TCP localhost 49186 13.107.4.50 80 ESTABLISHED
  60. stub[1].exe 224 TCP localhost 49188 91.192.100.11 7077 SYN_SENT
  61.  
  62. proc
  63. --------------
  64. "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde
  65. ...
  66. "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" -Embedding
  67. "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" -Embedding
  68. C:\tmp\stub[1].exe
  69. "C:\Program Files (x86)\Microsoft Office\Office12\excelcnv.exe" -Embedding
  70.  
  71. persist
  72. --------------
  73. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 09.05.2019 12:46
  74. ARP Service witneyer omnipotentiality
  75. c:\users\operator\appdata\roaming\9907dcbd-0284-49da-87e9-3f380347acb7\arp service\arpsv.exe 02.11.1993 13:41
  76.  
  77. drop
  78. --------------
  79. C:\tmp\stub[1].exe
  80. C:\Users\operator\AppData\Roaming\9907DCBD-0284-49DA-87E9-3F380347ACB7\ARP Service\arpsv.exe
  81.  
  82. # # #
  83. https://www.virustotal.com/gui/file/6be4c966edc63f37f52fc3a935344f634a8bb064d97200a31c0a3d2459ceda26/details
  84. https://www.virustotal.com/gui/file/0637afed4d69d13579b0f046e8897d4559fd0c3a4d77be16e8d00b23f6c38500/details
  85. https://www.virustotal.com/gui/file/17abc93230013c514555b8c99fdc359aa73427d47b409d643dc2c6a7d20d8961/details
  86. https://www.virustotal.com/gui/file/56f4a8947d55e20bc17f7e05dcc7484940c19845366c3e22ffa4f02e7cffd1cb/details
  87. https://analyze.intezer.com/#/analyses/7f554b60-55ba-48f7-b83c-750c6f31a756
  88.  
  89. VR
Advertisement
Add Comment
Please, Sign In to add comment