Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: EMOTET
- CYBERCHEF RECIPE TO GET URLS FROM THE BASE64-ENCODED POWERSHELL SCRIPT
- ----------------------------------------------------------------------
- From_Base64('A-Za-z0-9+/=',true)
- Decode_text('UTF-16LE (1200)')
- Split('*','\\n')
- Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'`'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'=Y3nkOs'},' ',true,false,true,false)
- Split('@','\\n')
- Find_/_Replace({'option':'Simple string','string':'w]xm[v'},'http',true,false,true,false)
- Extract_URLs(false)
- SENDERS OBSERVED
- MALDOC DISTRIBUTION URLS
- http://101bestresumes.com/wp-content/YqNRQcEOKpLonDHgvFo
- http://2posh.com/content/HfvdZ6JdUZnRKImchViGg
- http://bikemyday.se/wp-includes/oFlOxwTkHaWB
- http://editor.mycompanyadmin.com/cgi-bin/xyup87ko7f
- http://gpatsatsia123-001-site1.gtempurl.com/content/c4JFU9CVvbpD6nE0cu3BQ9JChpxCH0N8vijUGPrSJCXNiYF
- http://highlandslasvegas.atakdev.com/elite-dangerous-80no0/hyNCvpykM38TCHCHBtumlqWMosQ8vBkVJfIwtxNwDYEk8
- http://humach.com.my/wp-includes/oTn9pc96W46PSSAk5DlJGmTdUdkL154JaLYAxubxZ5aXf9
- http://kongjiantang.com/s/Qobgq5n36WJYRYWaRkNToQcn0J1sEAye0B
- http://lpgvitarakchayanalimited.in/hts-cache/ozRcoAzSNHssbEHZEl2lcCAGVwn9FLPjkBFS
- http://natvivers.com/wp-admin/tKmPyaWRTpTOaaTzau5bQAH60u
- http://obedient4dogs.com/motorola-radius-vdhr9/J7CgtbydjP00dN3Wvncp6e5tP6NNx6ppgJHvRHnzKIaGgPHCsTAUcaqpYbX6
- http://ope.co.ke/dup-installer/W49vnwLVfP9P6BVXqmxfiOuwoqn8LLQ66KRriQ6N804yVwWBpS0nADUXAjqyx5huDrgqT
- http://porlacalledelmedio.com/device-unlock-xlzl9/UqaqjBsMPt2loEQ5sJ45vwskI7AguuDKiAsNUU09gWG8jyHMx3ALyeMphHpm
- http://printfactory.mk/tetrapneumonous/P80VSnrxyn0q65OskSma2pBBZAlic4L16hQ7qSrJjbNkAVdOr4YUQSBXJqhuhihzbh04d
- http://readwritecomprehend.com/rwcstaging2/EXFibFHUdbgRRLzm5PgTzLV3VPkaUqCr8FnL2DYMMTedNZRidu3I
- http://riandutra.com/css/CyyQ5cSPZS9jU55gv9S5wmkdGInQAvVtwVM3SUe6muEN
- http://shumiao.web32.gufra.cn/sys-cache/4bm8b3tR501ZMXG7iefoprFBl9OPtwG7C7JHRfBPZGzVo3zHqb78euUNNxJiR0oXJB
- http://tasteoff.com/q/OpDqeTybIkBrUeUyOmmAoBeR
- http://wagnerbandeira.com.br/wp-admin/70hEzt62Bii0gBzEJ
- http://web.newinnovationtechnology.com/wp-includes/mwcqz4I51bJpixDmaRlOfss079x1vPxVmAzoHqiUkdnUx5nX3ocbRH67Rpmwx5liD
- http://wildtrust.mediadevstaging.com/w/BLkgoLFeN5do2I1r2Xm4XHrwIEnGQvNttwYWt4o9J7eoLFpu9mLHxnaN7qusU1cr7ixJ
- http://www.6ixbling.com/wp-admin/TV9qgAxQRUVCUmaBDu
- http://www.achutamanasa.com/media/jKSLHIcLhpJ4D8q64FQmm7J
- http://www.feroxtrade.com/wp-includes/UmpcBksf9hWxdhYZaoRfwAQmIdKmZ9M2vV0M7IwP4Mw3IezR88LoxWJ9dbw
- http://www.mahaexam.com/write-for-ef1wf/mxKtddELjSRZrAyOYyLRaiCxpHFLTqFOqhgz7UJpnZZZVJaPltKT3KwBHxX
- http://www.stmarouns.nsw.edu.au/paypal/sCEbAADIKittcJeww2O12FWBMXDxs2IJcWVekbkiAcF4kTf0F4ngVcZZ01FCa7eiyT
- http://www.suhangzhou.club/wp-admin/YGRmwZmiiPLvmQBYiMYoipQ0Lpof
- http://www.toplevel.com.br/medico/RuFF8m0jqCTqU81JIEynpDQgNvyD9JbSYNPS04w833jj9JcAdfZ
- https://archersrocksafaris.co.za/kaspersky-india-6fouf/v1rIjpF4R26YF899KdP2JW0nNKKlWZ4mbxsLcvWYYY2YTP9VaWBaEAijmDQ5O3
- https://brany-profimar.sk/g/8plrj6ossBkAVYT3PpMHXO32WNW2g9GmNO
- https://confinementxxx.com/have-a-ogtn/BbU1zz40LtzharekOxNx2C1J6Hdj7ZHwc7zTvk4tH
- https://confinementxxx.com:443/have-a-ogtn/BbU1zz40LtzharekOxNx2C1J6Hdj7ZHwc7zTvk4tH
- https://davestrades.com/wp-content/0Mz0PWeEKSy0j1TME8HbaaguB1
- https://dekhocampus.com/content/nhxKcdWhCE2d6mQdTHO5avuyk
- https://dmhhealthcare.com/vendor/DjG0L7bjX0cXMYS4QMguvwhIrdpfY7
- https://extrovertoffers.com/wp-includes/CCxUlwwZgPuqO4dNtDETT4qZUOWtyEXW668KyBuVqD92eL1Eu2CerLi8S
- https://hakm.ir/wp-admin/yGJ4IyOoc3fI0VQPf8DDXzaI4C
- https://humach.com.my/wp-includes/oTn9pc96W46PSSAk5DlJGmTdUdkL154JaLYAxubxZ5aXf9
- https://japan-crowdfunding.com/wp-admin/PfGLuo5DhKjQX7U
- https://luatsupro.com.vn/aimsweb-plus-czyqd/f9SNNSUOFpFF2glG8I
- https://natvivers.com/wp-admin/tKmPyaWRTpTOaaTzau5bQAH60u
- https://phulwariya.com/cgi-bin/btFdCAWZm4S8ZDQcMgrilzSlbHEfTzmHUzLMijzBxGb2jA5REmIaFolUaujdDsqy
- https://radioclype.scola.ac-paris.fr/wp-admin/js/widgets/kiqjl3pchfKPsKq1XbGlqKPlxE5bbg0031LLU8gjNNfI7hqQv
- https://shopping121.com/content/koFceSU8eLBVuibtKaeTzDlmum9dHpRvOzI1DpV6sjFClnGBO8teFuYAGCaCVuBqRRzZCE
- https://tasteoff.com/q/OpDqeTybIkBrUeUyOmmAoBeR
- https://thedarkweb.biz/wp-includes/GM8JAVJ0NrwxYbCCDN466vcYmzEv
- https://www.bpsklmp.com/slope-of-fklqm/WAwBh0V1Ul0AwVnLC59T7neQG3ydrQmczoB6G2MXr5wrpLTzlMEw
- https://www.ladinkids.com/how-to-vu45k/0NmnfmgalgorUCURYXHpal7bbKRXjx13cZaXZWDjhUd22WVYSnKgtHiPQyq2Bxoa
- https://www.mahaexam.com/write-for-ef1wf/mxKtddELjSRZrAyOYyLRaiCxpHFLTqFOqhgz7UJpnZZZVJaPltKT3KwBHxX
- https://www.obraprimaconstrucao.com.br/wp-admin/ObAcTwtC6jXgLylgATFc7JcZXESkyy9ngsqn4Mo1AdNZqOigWx5XCnS
- https://www.teelekded.com/cgi-bin/2pBTfjJamlhhEeO6wXz5gyi1m2kcBryox2KpXIp7QWrLLuBeaf
- https://www.tocaima.co/wp-includes/dj5Aol1nNnZJdyzVqURFh2LoPouZCEyok8NDYuoeW
- 101bestresumes.com
- 2posh.com
- 6ixbling.com
- ac-paris.fr
- achutamanasa.com
- archersrocksafaris.co.za
- atakdev.com
- bikemyday.se
- bpsklmp.com
- brany-profimar.sk
- confinementxxx.com
- davestrades.com
- dekhocampus.com
- dmhhealthcare.com
- extrovertoffers.com
- feroxtrade.com
- gtempurl.com
- gufra.cn
- hakm.ir
- humach.com.my
- japan-crowdfunding.com
- kongjiantang.com
- ladinkids.com
- lpgvitarakchayanalimited.in
- luatsupro.com.vn
- mahaexam.com
- mediadevstaging.com
- mycompanyadmin.com
- natvivers.com
- newinnovationtechnology.com
- nsw.edu.au
- obedient4dogs.com
- obraprimaconstrucao.com.br
- ope.co.ke
- phulwariya.com
- porlacalledelmedio.com
- printfactory.mk
- readwritecomprehend.com
- riandutra.com
- shopping121.com
- suhangzhou.club
- tasteoff.com
- teelekded.com
- thedarkweb.biz
- tocaima.co
- toplevel.com.br
- wagnerbandeira.com.br
- DOCUMENT FILE NAMES
- 7657919.doc
- AG-9712 Medical report Covid-19.doc
- Contact.doc
- COVID-19 report 01 12 2021.doc
- form.doc
- INV #0130074 FOR PO #0013243191.doc
- Inv LK-6634.doc
- Invoice #162719455.doc
- IRS_32100413_01122021.doc
- IRS_75066580_01122021.doc
- Report.doc
- Statement.doc
- Tax Return Transcript.doc
- YS-9522 Medical report Covid-19.doc
- DOCUMENT FILE HASHES
- 02e4c94fb021ce63caa36b0a3589ad3e
- 1c4db428a54dc913baf7db205d6884e0
- 3d89f8df471cbdee0c81c4e612a0343b
- 62d459ee60964e0fe72cc81e884be041
- 688a9919c56fb3f1b96de6844a02e378
- 7290a2a1b0e866d633befa7990fab059
- a060dcb3303867c6db1bdf5c05d97889
- b2f96be3f6361ac01b00de649dc26647
- b57ceb9470d4157036978896a8cfb2d4
- db47d60d98573837ee6b074b5f45351c
- f1d05ff1a1a3fd1fa09bff8a3b76d158
- f620ae53cd35a1ed01fbf474fc871b2f
- fd8fe5fe8a2fc4303f6fa8888ef89f32
- PAYLOAD FILE HASHES
- 0bfcf285d21db6a1d7969f11135bbf83
- 238a0e860a00ea4cc8ee2af05f2fbddf
- 2ae4683acdf3b0a7f513bdd20f9a818a
- 2d16022994972ed31beb862d44257387
- 5ce1eef2cc3055ae4942dc1a64b4223b
- 619272e3686141512fc513c5b4d27574
- 6a4575796c00181293c0054b4296859b
- 6a5333652a2431acc332947f5e3e29e6
- a97f77cf7a5b21100f7d8236d1553f8e
- b8883c58204443338d84cf96a63ae65f
- da852df0e170fbf8fc661f9f6da42947
- e60fa0cccceb55351bed4314b1d9873f
- eedc8adbf48f6b2c1122e7df351b730a
- fef02e92b737b746f56ab07a1a558741
- EMOTET PAYLOAD URLs
- http://abdindash.xyz/b/Yonhx/
- http://akybron.hu/wordpress/Triedit/
- http://angel2gether.de/BlutEngel/SpeechEngines/
- http://avadnansahin.com/wp-includes/w/
- http://baselinealameda.com/j/uoB/
- http://djsrecord.com/wp-includes/abop/
- http://giannaspsychicstudio.com/cgi-bin/Systems/
- http://hellas-darmstadt.de/cgi-bin/ZSoo/
- http://holonchile.cl/cgi-bin/System32/
- http://members.nlbformula.com/cgi-bin/Microsoft.NET/
- http://mmo.martinpollock.co.uk/a/SQSGg/
- http://shulovbaazar.com/c/bcL6/
- http://solicon.us/allam-cycle-1c4gn/f5z/
- http://thenetworker.ca/comment/8N4/
- http://uhk.cncranes.com/ErrorPages/3/
- http://www.agricampeggiocortecomotto.it/wp-admin/s7p1/
- http://www.mitraship.com/wp-content/ZKeB/
- http://www.riparazioni-radiotv.com/softaculous/DZz/
- https://altcomconstruction.com/wp-includes/or7/
- https://capturetheaction.com.au/wp-includes/Yjp/
- https://cavallarigutters.com/samsung-chromebook-etswp/Wdeiub/
- https://craku.tech/h/iXbreOs/
- https://lastfrontierstrekking.com/new/2OaabFU/
- https://mybusinessevent.com/tiki-install/e/
- https://nicoblogroms.com/c/V9w0b5/
- https://norailya.com/drupal/4zKMm/
- https://remediis.com/t/gm2X/
- https://shulovbaazar.com/c/bcL6/
- https://thenetworker.ca/comment/8N4/
- https://trayonlinegh.com/cgi-bin/HBPR/
- https://vysimopoulos.com/d/NF/
- https://watchnshirt.com/y/L7z9YcA/
- https://www.impipower.com/wp-content/U/
- https://www.inkayniperutours.com/druver/LtcG/
- https://www.starlingtechs.com/GNM/
- https://www.taradhuay.com/d/oT5uG/
- abdindash.xyz
- agricampeggiocortecomotto.it
- akybron.hu
- altcomconstruction.com
- angel2gether.de
- avadnansahin.com
- baselinealameda.com
- capturetheaction.com.au
- cavallarigutters.com
- cncranes.com
- craku.tech
- djsrecord.com
- giannaspsychicstudio.com
- hellas-darmstadt.de
- holonchile.cl
- impipower.com
- inkayniperutours.com
- lastfrontierstrekking.com
- martinpollock.co.uk
- mitraship.com
- mybusinessevent.com
- nicoblogroms.com
- nlbformula.com
- norailya.com
- remediis.com
- riparazioni-radiotv.com
- shulovbaazar.com
- solicon.us
- starlingtechs.com
- taradhuay.com
- thenetworker.ca
- trayonlinegh.com
- vysimopoulos.com
- watchnshirt.com
- EMOTET C2s
- http://161.49.84.2
- http://68.133.75.203:8080
- http://203.157.152.9:7080
- http://157.245.145.87:443
- http://195.159.28.244:8080
- http://175.103.38.146
- http://75.127.14.170:8080
- http://49.206.16.156
- http://185.208.226.142:8080
- http://91.93.3.85:8080
- http://58.27.215.3:8080
- http://172.96.190.154:8080
- http://143.95.101.72:8080
- http://162.144.145.58:8080
- http://172.193.14.201
- http://192.163.221.191:8080
- http://183.91.3.63
- http://2.82.75.215
- http://110.37.224.243
- http://54.38.143.245:8080
- http://37.205.9.252:7080
- http://152.32.75.74:443
- http://202.29.237.113:8080
- http://91.83.93.103:443
- http://37.46.129.215:8080
- http://27.78.27.110:443
- http://85.247.144.202
- http://110.1.113.179:443
- http://88.58.209.2
- http://120.51.34.254
- http://117.2.139.117:443
- http://188.166.220.180:7080
- http://79.133.6.236:8080
- http://115.79.195.246
- http://8.4.9.137:8080
- http://190.18.184.113
- http://5.79.70.250:8080
- http://201.193.160.196
- http://116.202.10.123:8080
- http://163.53.204.180:443
- http://201.212.61.66
- http://78.90.78.210
- http://110.172.180.180:8080
- http://122.116.104.238:8443
- http://192.241.220.183:8080
- http://172.104.46.84:8080
- http://203.160.167.243
- http://178.254.36.182:8080
- http://24.230.124.78
- http://50.116.78.109:8080
- http://103.80.51.61:8080
- http://103.229.73.17:8080
- http://70.32.89.105:8080
- http://46.32.229.152:8080
- http://186.96.170.61
- http://185.142.236.163:443
- http://190.85.46.52:7080
- http://74.208.173.91:8080
- http://223.17.215.76
- http://182.73.7.59:8080
- http://186.146.229.172
- http://198.20.228.9:8080
- http://192.210.217.94:8080
- http://188.226.165.170:8080
- http://46.105.131.68:8080
- http://91.75.75.46
- http://103.93.220.182
- http://2.58.16.86:8080
- http://195.201.56.70:8080
- http://139.5.101.203
- http://157.7.164.178:8081
- http://180.148.4.130:8080
- http://109.99.146.210:8080
- http://113.161.176.235
- http://139.59.12.63:8080
- http://113.203.238.130
- http://180.52.66.193
- http://139.59.61.215:443
- http://178.33.167.120:8080
- http://178.62.254.156:8080
- http://125.0.215.60
- http://203.56.191.129:8080
- http://82.78.179.117:443
- http://203.153.216.178:7080
- http://75.82.134.159:8080
- http://186.74.215.34
- http://157.245.123.197:8080
- http://50.116.111.59:8080
- http://188.165.214.98:8080
- http://85.105.111.166
- http://71.72.196.159
- http://120.150.60.189
- http://49.205.182.134
- http://98.109.133.80
- http://79.137.83.50:443
- http://167.114.153.111:8080
- http://5.39.91.110:7080
- http://74.208.45.104:8080
- http://89.106.251.163
- http://94.23.237.171:443
- http://86.98.21.56:443
- http://200.116.145.225:443
- http://37.139.21.175:8080
- http://78.182.254.231
- http://110.145.11.73
- http://50.245.107.73:443
- http://24.164.79.147:8080
- http://134.209.144.106:443
- http://5.2.212.254
- http://139.59.60.244:8080
- http://109.116.245.80
- http://181.171.209.241:443
- http://139.99.158.11:443
- http://104.131.11.150:443
- http://62.75.141.82
- http://174.118.202.24:443
- http://202.134.4.216:8080
- http://139.162.60.124:8080
- http://24.179.13.119
- http://70.183.211.3
- http://161.0.153.60
- http://154.0.8.2:443
- http://194.190.67.75
- http://2.58.16.89:8080
- http://89.216.122.92
- http://172.104.97.173:8080
- http://180.222.161.85
- http://87.106.139.101:8080
- http://37.187.72.193:8080
- http://74.128.121.17
- http://41.185.28.84:8080
- http://157.245.99.39:8080
- http://51.89.36.180:443
- http://190.103.228.24
- http://24.178.90.49
- http://75.109.111.18
- http://123.176.25.234
- http://64.207.182.168:8080
- http://70.92.118.112
- http://50.91.114.38
- http://185.201.9.197:8080
- http://62.171.142.179:8080
- http://168.235.67.138:7080
- http://24.69.65.8:8080
- http://202.134.4.211:8080
- http://109.74.5.95:8080
- http://95.213.236.64:8080
- http://61.19.246.238:443
- http://187.161.206.24
- http://110.145.101.66:443
- http://172.105.13.66:443
- http://118.83.154.64:443
- http://121.124.124.40:7080
- http://172.86.188.251:8080
- http://190.240.194.77:443
- http://119.59.116.21:8080
- http://181.165.68.127
- http://203.153.216.189:7080
- http://75.177.207.146
- http://67.170.250.203:443
- http://95.9.5.93
- http://66.57.108.14:443
- http://59.21.235.119
- http://138.68.87.218:443
- http://93.146.48.84
- http://47.144.21.37
- http://84.232.252.202:443
- http://115.94.207.99:443
- http://217.20.166.178:7080
- http://144.217.7.207:7080
- http://173.70.61.180
- http://188.219.31.12
- http://185.94.252.104:443
- http://136.244.110.184:8080
- http://194.4.58.192:7080
- http://78.24.219.147:8080
- http://172.125.40.123
- http://176.111.60.55:8080
- http://78.188.225.105
- http://74.58.215.226
- http://220.245.198.194
- http://190.29.166.0
- http://197.211.245.21
- http://74.40.205.197:443
- http://190.251.200.206
- http://24.231.88.85
- http://69.49.88.46
- http://62.30.7.67:443
- http://46.105.131.79:8080
- http://78.189.148.42
- http://75.188.107.174
- http://90.160.138.175
- http://179.233.3.89
- http://201.163.74.204
- http://203.157.152.9:7080
- http://157.245.145.87:443
- http://195.159.28.244:8080
- http://175.103.38.146
- http://49.206.16.156
- http://190.85.46.52:7080
- http://27.78.27.110:443
- http://203.160.167.243
- http://110.1.113.179:443
- http://78.90.78.210
- http://143.95.101.72:8080
- http://163.53.204.180:443
- http://122.116.104.238:8443
- http://161.49.84.2
- http://46.32.229.152:8080
- http://110.172.180.180:8080
- http://178.254.36.182:8080
- http://195.201.56.70:8080
- http://113.161.176.235
- http://2.58.16.86:8080
- http://103.93.220.182
- http://188.226.165.170:8080
- http://85.247.144.202
- http://2.82.75.215
- http://116.202.10.123:8080
- http://120.51.34.254
- http://188.166.220.180:7080
- http://139.59.61.215:443
- http://103.80.51.61:8080
- http://91.93.3.85:8080
- http://117.2.139.117:443
- http://24.230.124.78
- http://54.38.143.245:8080
- http://58.27.215.3:8080
- http://50.116.78.109:8080
- http://91.75.75.46
- http://178.33.167.120:8080
- http://5.79.70.250:8080
- http://201.212.61.66
- http://185.142.236.163:443
- http://186.146.229.172
- http://192.241.220.183:8080
- http://185.208.226.142:8080
- http://139.5.101.203
- http://37.205.9.252:7080
- http://68.133.75.203:8080
- http://172.193.14.201
- http://88.58.209.2
- http://125.0.215.60
- http://202.29.237.113:8080
- http://110.37.224.243
- http://182.73.7.59:8080
- http://178.62.254.156:8080
- http://192.163.221.191:8080
- http://162.144.145.58:8080
- http://113.203.238.130
- http://75.127.14.170:8080
- http://186.96.170.61
- http://103.229.73.17:8080
- http://139.59.12.63:8080
- http://183.91.3.63
- http://115.79.195.246
- http://201.193.160.196
- http://198.20.228.9:8080
- http://8.4.9.137:8080
- http://190.18.184.113
- http://172.104.46.84:8080
- http://172.96.190.154:8080
- http://82.78.179.117:443
- http://157.7.164.178:8081
- http://109.99.146.210:8080
- http://203.56.191.129:8080
- http://37.46.129.215:8080
- http://74.208.173.91:8080
- http://223.17.215.76
- http://79.133.6.236:8080
- http://180.148.4.130:8080
- http://70.32.89.105:8080
- http://152.32.75.74:443
- http://46.105.131.68:8080
- http://192.210.217.94:8080
- http://91.83.93.103:443
- http://203.153.216.178:7080
Add Comment
Please, Sign In to add comment