VRad

#dridex_010221

Feb 2nd, 2021 (edited)
266
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.90 KB | None | 0 0
  1. #IOC #OptiData #VR #dridex #macro #regsvr32 #dll
  2.  
  3. https://pastebin.com/hp4fvBqb
  4.  
  5. previous_contact:
  6.  
  7. attack_vector
  8. --------------
  9. email attach .zip (passwd) > .xlsm > macro > EXCEL download > regsvr32.exe > %temp%\%name%.dll
  10.  
  11. email_headers
  12. --------------
  13. n/a
  14.  
  15. files
  16. --------------
  17. SHA-256 b721618810b06ed4089d1469fc5c5b37be1a907fc1ae14222f913c6e2b0001c2
  18. File name printouts_of_outstanding_as_of FEB_01_2021.xlsm [ Excel Microsoft Office Open XML Format document (with Macro)]
  19. File size 115.81 KB (118587 bytes)
  20.  
  21. SHA-256 2954fff16d963d718ba0518ebdcadb61c71bf4d5cdd13d4c6bc7058329229c21
  22. File name ekwhaz.dll
  23. File size 584.50 KB (598528 bytes)
  24.  
  25. activity
  26. **************
  27. PL_SCR https://smithcalendar.cstdevs.com/qv9p5brpm.zip
  28.  
  29. C2 77.220.64.131:443
  30. 5.196.204.251:5037
  31. 192.99.41.136:981
  32. 24.229.3.146:4664
  33.  
  34. netwrk
  35. --------------
  36. 109.203.107.71 talklivebuddy.com Client Hello
  37. 77.220.64.131 Client Hello
  38. 5.196.204.251 50598 → 5037 [SYN]
  39. 192.99.41.136 50599 → 981 [SYN]
  40.  
  41. comp
  42. --------------
  43. EXCEL.EXE 3200 TCP 109.203.107.71 443 ESTABLISHED
  44. regsvr32.exe 3464 TCP 77.220.64.131 443 ESTABLISHED
  45. regsvr32.exe 3464 TCP 5.196.204.251 5037 ESTABLISHED
  46. regsvr32.exe 3464 TCP 192.99.41.136 981 ESTABLISHED
  47.  
  48. proc
  49. --------------
  50. "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" /e
  51. "C:\Windows\System32\regsvr32.exe" -s C:\Users\operator\AppData\Local\Temp\kwiehbiv.dll
  52.  
  53. persist
  54. --------------
  55. n/a
  56.  
  57. drop
  58. --------------
  59. C:\temp\~DFD866A6C2D60EA793.TMP
  60. C:\Users\operator\AppData\Local\Temp\kwiehbiv.dll
  61.  
  62. # # #
  63. https://www.virustotal.com/gui/file/b721618810b06ed4089d1469fc5c5b37be1a907fc1ae14222f913c6e2b0001c2/details
  64. https://www.virustotal.com/gui/file/2954fff16d963d718ba0518ebdcadb61c71bf4d5cdd13d4c6bc7058329229c21/details
  65. https://analyze.intezer.com/analyses/124e33ce-91e1-46be-b8f4-b154bc4d9104
  66.  
  67. VR
Add Comment
Please, Sign In to add comment