ExecuteMalware

2020-09-25 Emotet IOCs

Sep 25th, 2020
3,278
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.65 KB | None | 0 0
  1. THREAT ATTRIBUTION: EMOTET
  2.  
  3. From_Base64('A-Za-z0-9+/=',true)
  4. Decode_text('UTF-16LE (1200)')
  5. Split('*','\\n')
  6. Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
  7. Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
  8. Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
  9. Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
  10. Extract_URLs(false)
  11.  
  12.  
  13. SENDERS OBSERVED
  14.  
  15. MALDOC DISTRIBUTION URLS
  16. http://165.22.71.24/sys-cache/public/
  17. http://ambulanceservice.nl/export/file/gz9ogci1hj/
  18. http://andrademendonca.com.br/wp-content/2YL86MTKGTJKHU/Oib5nGCJOw/
  19. http://bhntmanulife.net/o3ywyha/3s7pts/
  20. http://bruset.no/picture_library/browse/UniDFobbgRfs3vceLFig/
  21. http://cnaantours.co.il/wp-content/paclm/s0dx79619888547440208o2c6ff4599prxr/
  22. http://cojestgrane.simplicitygames.pl/songs/eTrac/cc9u9y3uwjk/
  23. http://crupie.com.br/teste/A4X8L324WL03/zueVKjOlYzXA6Sd4Vrc/
  24. http://dagostim.com.br/rss/docs/UCv65TLbvo2HErwc/
  25. http://dev.dosily.in/wp-content/parts_service/olCCW8OpAYq3wKxDZXz/
  26. http://dpsolutions.com.my/wp-admin/esp/h591vQOmqGv6oYCsU5/
  27. http://geisterhouse.com/cgi-bin/Pages/EECRC3H4qx/
  28. http://hotelshivansh.com/UserFiles/attachments/gqrg5oms/mq56639070655100lbcddfcv28nkol2w/
  29. http://idioticmedia.in/img/j6rzwe37t97a/h1ovq10871580452egr4iofqygr42lkcmgtkt/
  30. http://irvingstudios.com/photos/OCT/npji2uwsmih/
  31. http://kedaiabah.com/wp-includes/INC/7XXIEK68lF/
  32. http://lagera.com/images/eTrac/aUQK2Fav5TA9UNeGp7Ol/
  33. http://leapmom.com/ukeol/browse/
  34. http://mesdelicesitaliens.fr/wp-admin/eTrac/7uVbSf4mfxl3/
  35. http://mrveggy.com/erros/Document/8ysk21443893413537pzbh5hlpb/
  36. http://mystylu.com.tw/wp-admin/LLC/qAcBvISwLyWaaIzSkY6N/
  37. http://newideaco.ir/wp-content/ligzu9q4/
  38. http://onex.co.za/journal/LLC/MNWxStgCzpFsHTKxYxrx/
  39. http://otto-nautic.ro/wp-content/Pages/KUEUwtz9Vlmn/
  40. http://pellesbar.co.il/wp-content/Pk7Yk0JTtPSz8Njh/
  41. http://petercollie.com/2014.old.site/DOC/F3LLuJcONxTV7Ju5Bm/
  42. http://robm.fastmail.fm/virus/Electronic%20form.doc/
  43. http://rydchile.cl/wp-content/Document/RFxtxKpb6pPDV/
  44. http://sjhoops.com/Scan/y42MRV0Azlu7U/
  45. http://snpconsulting.com.au/Documents/Scan/Ja66qlKdRnEZPNMoKim/
  46. http://theusacommunity.com/wp-content/parts_service/xtg9rch/
  47. http://vniel.co.kr/gnuboard/data/Scan/amowVegfRT9Ja/
  48. http://vrindapublicschool.com/cgi-bin/attachments/mz8l9dxzhsiu/
  49. http://wafeeqa-realestate.com/integrity/invoice/3flecc1qzpfq/
  50. http://www.duosite.com.br/host/attachments/uoG9VBQ5UYxGz/
  51. http://www.jimenezabogados.mx/Firmas/browse/aBFMMSuuOcF/
  52. http://www.mystylu.com.tw/wp-admin/LLC/qAcBvISwLyWaaIzSkY6N/
  53. http://www.shanchuangjiaoyu.cn/wp-includes/INC/b4295516781073uvh74oqkpy3osrfy4xw/
  54. http://www.streamnew.com/49cfzk/FXc9xTSsme14jh3q/
  55. https://construbelcaxias.com.br/wp-admin/esp/
  56. https://dev.dosily.in/wp-content/parts_service/olCCW8OpAYq3wKxDZXz/
  57. https://dev.omniroom.ru/sys-cache/Document/z2cr86eqer/m462238043734qn5o01f9b5dh7iyj2/
  58. https://dev.toca.store/wp-includes/sodium_compat/INC/dXRePll1aoe/
  59. https://global-solutions.co/sites/invoice/5gio89oh0034/wdi329549337635775zi6xz8khpe81ymdzboulx/
  60. https://jrvservices.com.br/JRV_ANTIGO/LLC/c0C5R8Kbbt2AcE0GGb43/
  61. https://laminatedtube.com/site/parts_service/U8QeEk6yjjri3oVBpI/
  62. https://lkfx168.com/wp-content/Overview/9FKkvZwpySR4hnZpY/
  63. https://mrveggy.com/erros/Document/8ysk21443893413537pzbh5hlpb/
  64. https://office.horussolution.com/files/Scan/3RcAVwetSPtsHa/
  65. https://research.kku.ac.th/sys-cache/3774EPWE8VDST/sFWJJzWQW10lG6vVxg/
  66. https://www.breedenandsilver.com/wp-content/qgtNLIQxb0YR8lg/
  67. https://www.duosite.com.br/host/attachments/uoG9VBQ5UYxGz/
  68.  
  69. ambulanceservice.nl
  70. andrademendonca.com.br
  71. bhntmanulife.net
  72. breedenandsilver.com
  73. bruset.no
  74. cnaantours.co.il
  75. simplicitygames.pl
  76. construbelcaxias.com.br
  77. crupie.com.br
  78. dagostim.com.br
  79. dosily.in
  80. omniroom.ru
  81. toca.store
  82. dpsolutions.com.my
  83. duosite.com.br
  84. geisterhouse.com
  85. global-solutions.co
  86. hotelshivansh.com
  87. idioticmedia.in
  88. irvingstudios.com
  89. jimenezabogados.mx
  90. jrvservices.com.br
  91. kedaiabah.com
  92. lagera.com
  93. laminatedtube.com
  94. leapmom.com
  95. lkfx168.com
  96. mesdelicesitaliens.fr
  97. mrveggy.com
  98. mystylu.com.tw
  99. newideaco.ir
  100. horussolution.com
  101. onex.co.za
  102. otto-nautic.ro
  103. pellesbar.co.il
  104. petercollie.com
  105. research.kku.ac.th
  106. fastmail.fm
  107. rydchile.cl
  108. shanchuangjiaoyu.cn
  109. sjhoops.com
  110. snpconsulting.com.au
  111. streamnew.com
  112. theusacommunity.com
  113. vniel.co.kr
  114. vrindapublicschool.com
  115. wafeeqa-realestate.com
  116.  
  117. DOCUMENT FILE HASHES
  118. a24beb27d28b13533316fe757c85b55a
  119. 88a55983f61c1aed72b2234aaea3b46a
  120. de0918d2d5f0317258f3eba7cb980801
  121.  
  122. ZIP FILE HASHES
  123. b43a53fbbbdc90a3af803672ed879495
  124.  
  125. PAYLOAD FILE HASHES
  126. 0aea8053cb10df62c9ce1a3d3b4f2cc1
  127. 0c904f30c7eb420b85ef84b807fe608b
  128. 0ec3dcc90fd1d792fc22f7004f1cb9b8
  129. 1d89e0b816661c04137495f9c09f77bc
  130. 304cf24a24f191e343da87c618b09a27
  131. 36e99bd97717819ac188dc0393bb7ff1
  132. 3bcf1d1eecddc5e93374d32fb2c7959b
  133. 3c8707edf2bacaf969813db1dc0b8dbd
  134. 7d120567c2d847376ca00f0f04cf3041
  135. 95e277536f77b8679d06c7c85cd37ef5
  136. a8f4445f5e6238918b85133b70a54397
  137. ab56932ca1c95bb8a503216c0154faae
  138. bff40d6831993432a189ccc8dee24447
  139. efc297cc9a843063b62fe77608649f83
  140.  
  141. EMOTET PAYLOAD URLs
  142. http://13.229.25.57/7xdfb/jpA/
  143. http://bavhome.com/wp-content/td/
  144. http://binarystationary.com/cgi-bin/5rM/
  145. http://bodenstein.co.za/images/Gdc2/
  146. http://bomfuturoadesivos.com/vdo/pDT4/
  147. http://calledtochange.org/CalledtoChange/V/
  148. http://cuadros.pe/personal_sector/gKi/
  149. http://daoisthealing.com/cgi-bin/c/
  150. http://dentalalliance.se/wp-admin/iBkjpN5De/
  151. http://earthinnovation.org/pcimonitor/mnNHQNm3/
  152. http://eno.si/administrator/luL1uq/
  153. http://fmcav.com/images/ZQF/
  154. http://glassesnepal.com/gxlaf/tQ6/
  155. http://hercinovic.com/cgi-bin/mZt/
  156. http://ibccglobal.com/thankyou2/ARA/
  157. http://infoquick.co.uk/event_ticket/bIJuS/
  158. http://kharazmischl.com/w/k/
  159. http://must-in.com/wp-admin/0/
  160. http://ottimade.com/wp-content/E/
  161. http://paulscomputing.com/CraigsMagicSquare/gQ1/
  162. http://playschoolmatritva.com/cgi-bin/Cqw/
  163. http://qualitychildcarepreschool.com/emqblk/wnwsegpnq/
  164. http://secrice.com/writing/2003/0nI/
  165. http://umapreowned.com/uu1e/KxHmG/
  166. http://vnshinejsc.com/wp-content/IN1P/
  167. http://work.digitalvichar.com/1mv7clu/o/
  168. http://www.bismarjeparamebel.com/u/pCp/
  169. http://wynn838.com/wp-content/Eo/
  170. http://yatkiralama.online/wp-content/BG2hBQR1L/
  171. https://ajstudiollc.com/cgi-bin/MiL/
  172. https://artewebestudio.com/cgi-bin/A8UfqtzOx/
  173. https://cimsjr.com/hospital/Fh4/
  174. https://finewines.com.sg/wset-2-registration/ObrD/
  175. https://fotoobjetivo.com/wp-content/x1/
  176. https://heartssetfree.org/9c950e/FnH/
  177. https://jeffdahlke.com/css/3u/
  178. https://khvs.vrfantasy.gallery/igiodbck/eXq/
  179. https://kodiakheating.com/ldnha/ybI/
  180. https://konican.com/cgi-bin/gz/
  181. https://lojaskock.com.br/BACKUP/AW/
  182. https://nbiz.tk/wp-admin/idmW/
  183. https://online24h.biz/wp-admin/t/
  184. https://scyzm.net/wp-content/j/
  185. https://www.pxid360.com/wp-admin/vMPE8y9i/
  186.  
  187. ajstudiollc.com
  188. artewebestudio.com
  189. bavhome.com
  190. binarystationary.com
  191. bismarjeparamebel.com
  192. bodenstein.co.za
  193. bomfuturoadesivos.com
  194. calledtochange.org
  195. cimsjr.com
  196. cuadros.pe
  197. daoisthealing.com
  198. dentalalliance.se
  199. digitalvichar.com
  200. earthinnovation.org
  201. eno.si
  202. finewines.com.sg
  203. fmcav.com
  204. fotoobjetivo.com
  205. glassesnepal.com
  206. heartssetfree.org
  207. hercinovic.com
  208. ibccglobal.com
  209. infoquick.co.uk
  210. jeffdahlke.com
  211. kharazmischl.com
  212. kodiakheating.com
  213. konican.com
  214. lojaskock.com.br
  215. must-in.com
  216. nbiz.tk
  217. online24h.biz
  218. ottimade.com
  219. paulscomputing.com
  220. playschoolmatritva.com
  221. pxid360.com
  222. qualitychildcarepreschool.com
  223. scyzm.net
  224. secrice.com
  225. umapreowned.com
  226. vnshinejsc.com
  227. vrfantasy.gallery
  228. wynn838.com
  229. yatkiralama.online
  230.  
  231. EMOTET C2s
  232. (107)
  233. http://12.163.208.58
  234. http://45.33.35.74:8080
  235. http://87.106.253.248:8080
  236. http://192.241.146.84:8080
  237. http://190.115.18.139:8080
  238. http://65.36.62.20
  239. http://170.81.48.2
  240. http://83.169.21.32:7080
  241. http://185.232.182.218
  242. http://190.2.31.172
  243. http://77.106.157.34:8080
  244. http://82.230.1.24
  245. http://202.4.58.197
  246. http://201.213.177.139
  247. http://78.249.119.122
  248. http://123.51.47.18
  249. http://77.90.136.129:8080
  250. http://60.93.23.51
  251. http://152.169.22.67
  252. http://190.117.79.209
  253. http://60.108.144.104:443
  254. http://213.197.182.158:8080
  255. http://82.76.111.249:443
  256. http://209.236.123.42:8080
  257. http://190.24.243.186
  258. http://177.74.228.34
  259. http://191.182.6.118
  260. http://96.245.123.149
  261. http://61.197.92.216
  262. http://1.226.84.243:8080
  263. http://111.67.12.221:8080
  264. http://216.47.196.104
  265. http://185.94.252.27:443
  266. http://70.116.143.84
  267. http://187.162.248.237
  268. http://217.13.106.14:8080
  269. http://80.11.164.185
  270. http://35.143.99.174
  271. http://190.190.148.27:8080
  272. http://219.92.13.25
  273. http://70.32.115.157:8080
  274. http://96.227.52.8:443
  275. http://51.75.33.127
  276. http://95.9.180.128
  277. http://174.113.69.136
  278. http://119.106.216.84
  279. http://111.67.77.202:8080
  280. http://91.105.94.200
  281. http://178.250.54.208:8080
  282. http://98.13.75.196
  283. http://2.36.95.106
  284. http://186.70.127.199:8090
  285. http://116.202.23.3:8080
  286. http://202.134.4.210:7080
  287. http://50.28.51.143:8080
  288. http://45.33.77.42:8080
  289. http://67.247.242.247
  290. http://137.74.106.111:7080
  291. http://85.214.26.7:8080
  292. http://181.30.61.163:443
  293. http://77.238.212.227
  294. http://185.215.227.107:443
  295. http://186.103.141.250:443
  296. http://50.121.220.50
  297. http://74.136.144.133
  298. http://104.131.41.185:8080
  299. http://61.92.159.208:8080
  300. http://104.131.103.37:8080
  301. http://51.15.7.189
  302. http://185.94.252.12
  303. http://94.176.234.118:443
  304. http://212.71.237.140:8080
  305. http://5.196.35.138:7080
  306. http://45.46.37.97
  307. http://70.32.84.74:8080
  308. http://199.203.62.165
  309. http://38.88.126.202:8080
  310. http://51.159.23.217:443
  311. http://155.186.0.121
  312. http://51.38.124.206
  313. http://181.129.96.162:8080
  314. http://64.201.88.132
  315. http://92.24.50.153
  316. http://189.2.177.210:443
  317. http://45.16.226.117:443
  318. http://76.168.54.203
  319. http://185.178.10.77
  320. http://220.109.145.69
  321. http://192.81.38.31
  322. http://68.183.170.114:8080
  323. http://177.73.0.98:443
  324. http://138.97.60.141:7080
  325. http://192.241.143.52:8080
  326. http://217.199.160.224:7080
  327. http://185.183.16.47
  328. http://177.129.17.170:443
  329. http://5.189.178.202:8080
  330. http://74.58.215.226
  331. http://51.255.165.160:8080
  332. http://12.162.84.2:8080
  333. http://149.202.72.142:7080
  334. http://87.106.46.107:8080
  335. http://188.135.15.49
  336. http://68.183.190.199:8080
  337. http://172.104.169.32:8080
  338. http://68.69.155.181
  339. http://72.47.248.48:7080
  340.  
  341. (103)
  342. http://49.243.9.118
  343. http://162.241.41.111:7080
  344. http://190.85.46.52:7080
  345. http://162.144.42.60:8080
  346. http://157.245.138.101:7080
  347. http://103.133.66.57:443
  348. http://167.71.227.113:8080
  349. http://80.200.62.81:20
  350. http://78.186.65.230
  351. http://185.142.236.163:443
  352. http://78.114.175.216
  353. http://202.166.170.43
  354. http://37.205.9.252:7080
  355. http://118.243.83.70
  356. http://116.202.10.123:8080
  357. http://223.135.30.189
  358. http://120.51.34.254
  359. http://139.59.61.215:443
  360. http://8.4.9.137:8080
  361. http://202.153.220.157
  362. http://179.5.118.12
  363. http://75.127.14.170:8080
  364. http://45.177.120.37:8080
  365. http://41.185.29.128:8080
  366. http://79.133.6.236:8080
  367. http://192.241.220.183:8080
  368. http://203.153.216.178:7080
  369. http://115.176.16.221
  370. http://113.161.148.81
  371. http://178.33.167.120:8080
  372. http://183.77.227.38
  373. http://46.105.131.68:8080
  374. http://181.95.133.104
  375. http://93.20.157.143
  376. http://172.105.78.244:8080
  377. http://139.59.12.63:8080
  378. http://190.192.39.136
  379. http://41.212.89.128
  380. http://27.73.70.219:8080
  381. http://109.206.139.119
  382. http://192.163.221.191:8080
  383. http://113.160.248.110
  384. http://182.227.240.189:443
  385. http://185.208.226.142:8080
  386. http://126.126.139.26:443
  387. http://185.80.172.199
  388. http://103.229.73.17:8080
  389. http://5.79.70.250:8080
  390. http://95.216.205.155:8080
  391. http://190.194.12.132
  392. http://37.46.129.215:8080
  393. http://51.38.201.19:7080
  394. http://195.201.56.70:8080
  395. http://175.103.38.146
  396. http://73.55.128.120
  397. http://74.208.173.91:8080
  398. http://189.150.209.206
  399. http://91.83.93.103:443
  400. http://86.57.216.23
  401. http://36.91.44.183
  402. http://181.80.129.181
  403. http://50.116.78.109:8080
  404. http://14.241.182.160
  405. http://60.125.114.64:443
  406. http://113.156.82.32
  407. http://190.191.171.72
  408. http://67.121.104.51:20
  409. http://111.89.241.139
  410. http://220.106.127.191:443
  411. http://46.32.229.152:8080
  412. http://115.79.59.157
  413. http://58.27.215.3:8080
  414. http://192.210.217.94:8080
  415. http://118.33.121.37
  416. http://169.1.211.133
  417. http://54.38.143.245:8080
  418. http://198.57.203.63:8080
  419. http://138.201.45.2:8080
  420. http://172.96.190.154:8080
  421. http://143.95.101.72:8080
  422. http://45.239.204.100
  423. http://103.93.220.182
  424. http://185.86.148.68:443
  425. http://119.92.77.17
  426. http://186.20.52.237
  427. http://115.79.195.246
  428. http://223.17.215.76
  429. http://77.74.78.80:443
  430. http://113.203.238.130
  431. http://220.147.247.145
  432. http://153.229.219.1:443
  433. http://187.189.66.200:8080
  434. http://103.80.51.61:8080
  435. http://27.7.14.122
  436. http://200.116.93.61
  437. http://182.253.83.234:7080
  438. http://91.75.75.46
  439. http://128.106.187.110
  440. http://113.193.239.51:443
  441. http://180.148.4.130:8080
  442. http://157.7.164.178:8081
  443. http://88.247.58.26
  444. http://37.187.100.220:7080
Add Comment
Please, Sign In to add comment