Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #Lokibot #ZIP
- https://pastebin.com/Wg4bSRFp
- previous_contact:
- 01/12/18 https://pastebin.com/w5Gy50d5
- 01/12/18 https://pastebin.com/JHBUsJ7k
- 28/11/18 https://pastebin.com/W0e6iWnc
- 28/11/18 https://pastebin.com/4hf0UEqM
- 16/10/18 https://pastebin.com/LPqjHUkQ
- 8/10/18 https://pastebin.com/cZxQGbyq
- 27/09/18 https://pastebin.com/5bpk5kKs
- FAQ:
- https://radetskiy.wordpress.com/?s=lokibot
- attack_vector
- --------------
- email attach pdf.arj(zip) > exe
- email_headers
- --------------
- Received: from sw0.sweimpo.cf (sw0.sweimpo.cf [185.62.189.148])
- for <user0@ou7.victim1.com>; Mon, 3 Dec 2018 12:31:37 +0200 (EET)
- (envelope-from y-tsuchiya@kenefsa.co.jp)
- Subject: Confirm INV
- To: user0@ou7.victim1.com
- From: "Capt Yuki" <y-tsuchiya@kenefsa.co.jp>
- Date: Mon, 03 Dec 2018 02:31:20 -0800
- files
- --------------
- SHA-256 39b378f0f90a24e027e282ab24c8c313cd85b137cb922f1eeb3e26ffb9f9eef4
- File name INV_992990018030-pdf.arj [Zip archive data, at least v2.0 to extract]
- File size 421.96 KB
- SHA-256 b37232f41cd805fc46f624b52f80dba06dfbeee03392ed048060988a1a6b7ff0
- File name INV_992990018030-pdf.exe [PE32 executable (GUI) Intel 80386, for MS Windows]
- File size 768.5 KB
- activity
- **************
- PL_GET: attach
- C2: h11p:\ 2979{.} my{.} to/obinna/king.php
- netwrk
- --------------
- 208.51.63.241 2979{.} my{.} to POST /obinna/king.php HTTP/1.0 Mozilla/4.08 (Charon; Inferno)
- comp
- --------------
- INV_992990018030-pdf.exe 3896 208.51.63.241 80 ESTABLISHED
- proc
- --------------
- C:\Users\operator\Desktop\INV_992990018030-pdf.exe
- persist
- --------------
- n/a
- drop
- --------------
- C:\Users\operator\AppData\Roaming\39B01F\FA74A3.exe
- C:\Users\operator\AppData\Roaming\39B01F\FA74A3.hdb
- # # #
- https://www.virustotal.com/#/file/39b378f0f90a24e027e282ab24c8c313cd85b137cb922f1eeb3e26ffb9f9eef4/details
- https://www.virustotal.com/#/file/b37232f41cd805fc46f624b52f80dba06dfbeee03392ed048060988a1a6b7ff0/details
- https://analyze.intezer.com/#/analyses/14f40b36-e8eb-4201-972b-b3cf960991d5
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement