Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] Dropper pattern:
- (FACT |Facture-(impayee-)?)(Nr\. |#)?[-0-9T]{4,15}\.doc
- [*] Host contacted to download paypload:
- hxxp://alicicek.com.tr/9DK4OC/
- hxxp://jpol.com/li8CyWi/
- hxxp://foodstyle.de/kNKqO/
- hxxps://silke-steinle.de/2hAuu3/
- hxxp://charcalla.com/BjmQyaB/
- hxxp://intrigueweb.com/iQV6A/
- hxxp://provanet.co.jp/u6CdB/
- hxxp://marugin.net/KexaQ/
- hxxp://intrigueweb.com/iQV6A/
- hxxp://provanet.co.jp/u6CdB/
- hxxp://marugin.net/KexaQ/
- hxxp://tulpconsult.nl/EMwiS/
- hxxp://tudointernet.com.br/6YXeSb/
- [*] Payload downloaded:
- https://www.virustotal.com/en/file/1b6b800646f9c3412bb10bf7703d4713874bc634c21e8ec2460a667c5a71c8d1/analysis/
- https://www.virustotal.com/en/file/85511c4588ce3b2fed557b17364471cf132cfaaa441f75b28604165af29913ee/analysis/
- [*] C&C contacted by the payload:
- 24.217.117.217
- 37.59.51.53:8080
- 72.52.216.110:8080
- 149.62.173.247:8080
- 50.84.95.206
- 106.187.91.235:8080
- 203.198.129.4:8080
- 89.186.26.179:8080
- [*] User-agent used by the payload to contact the C&C:
- mozilla/4.0 (compatible; msie 7.0; windows nt 6.1; wow64; trident/7.0; slcc2; .net clr 2.0.50727; .net clr 3.5.30729; .net clr 3.0.30729; infopath.3; .net4.0c; .net4.0e)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement