Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #formbook #RAR #EXE
- https://pastebin.com/1FMBBK3N
- previous_contact:
- 26/02/19 https://pastebin.com/yLu1cL9K
- 15/11/18 https://pastebin.com/VFG89LnT
- 14/11/18 https://pastebin.com/D6VPDyyz
- FAQ:
- attack_vector
- --------------
- email attach .RAR > .EXE
- email_headers
- --------------
- n/a
- files
- --------------
- SHA-256 fadf0395c50287c0981c0ba6a5dd94df18d574489760811484f79b678f62dadb
- File name PO19040302.rar [RAR archive data, v2e,]
- File size 259.53 KB (265759 bytes)
- SHA-256 03b325328922fd983ab4e2e8de3780c7b7711a14043103cc2d461e378638d640
- File name PO19040302.exe [PE32 executable (GUI) Intel 80386, for MS Windows]
- File size 552 KB (565248 bytes)
- activity
- **************
- netwrk
- --------------
- 192.252.146.28 efficientmechanical{.} com GET /su/?GT=iAQ...==&zl3D=Ul9L HTTP/1.1 Continuation noUA
- 184.168.221.96 istdama{.} com GET /su/?GT=+q5...==&zl3D=Ul9L&sql=1 HTTP/1.1 Continuation noUA
- 184.168.221.96 istdama{.} com POST /su/ HTTP/1.1 Mozilla/4.0
- 217.70.184.50 thecrudeco{.} com GET /su/?GT=SsW...==&zl3D=Ul9L&sql=1 HTTP/1.1 Continuation noUA
- 217.70.184.50 thecrudeco{.} com POST /su/ HTTP/1.1 Mozilla/4.0
- comp
- --------------
- explorer.exe 2045 TCP localhost 40321 192.252.146.28 80 ESTABLISHED
- explorer.exe 2045 TCP localhost 40376 184.168.221.96 80 ESTABLISHED
- explorer.exe 2045 TCP localhost 40387 217.70.184.50 80 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\PO19040302.exe
- C:\Users\operator\Desktop\PO19040302.exe
- C:\Windows\System32\netsh.exe
- C:\Windows\System32\cmd.exe /c del "C:\Users\operator\Desktop\PO19040302.exe"
- C:\Program Files\Mozilla Firefox\Firefox.exe
- C:\Program Files\Yv4bdn\pr6hzlkspx.exe
- C:\Program Files\Yv4bdn\pr6hzlkspx.exe
- C:\Windows\System32\netsh.exe
- C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}
- persist
- --------------
- n/a
- drop
- --------------
- C:\Program Files\Yv4bdn\pr6hzlkspx.exe
- # # #
- https://www.virustotal.com/gui/file/fadf0395c50287c0981c0ba6a5dd94df18d574489760811484f79b678f62dadb/details
- https://www.virustotal.com/gui/file/03b325328922fd983ab4e2e8de3780c7b7711a14043103cc2d461e378638d640/details
- https://analyze.intezer.com/#/analyses/dc1d2f98-3f81-4512-ac65-e38538335821
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement