Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #macro #adwind
- https://pastebin.com/v2kfP17r
- previous_contact:
- n/a
- FAQ:
- https://radetskiy.wordpress.com/2018/05/11/ioc_adwind_100518/
- attack_vector
- --------------
- email attach .DOC > macro > GET jar
- email_headers
- --------------
- Received: from lrwdd2.directrouter.com (lrwdd2.directrouter.com [206.123.119.186])
- Date: Mon, 05 Aug 2019 04:22:00 -0500
- From: cellardoor@palmerwines.com.au
- To: user00@victim77.com
- Subject: Fwd: Purchasing Oder
- X-Sender: cellardoor@palmerwines.com.au
- User-Agent: Roundcube Webmail/1.3.8
- files
- --------------
- SHA-256 ec845d4c57715e83a80467cfce273e3c54c89aca5229e3f2476057e234c1c0bd
- File name PO JAR.doc
- File size 508 KB (520192 bytes)
- SHA-256 a104db76b0b3b8387674918217806325a9db2cf0951e9ec9f88ff6a80d9585b7
- File name umucry.jar
- File size 652.17 KB (667818 bytes)
- activity
- **************
- PL_SCR
- h11ps\kcexports{.} me/umucry.jar
- C2
- 67.207.93.17
- 192.169.69.25
- netwrk
- --------------
- [ssl]
- 167.71.13.65 kcexports{.} me Client Hello
- comp
- --------------
- WINWORD.EXE 172 TCP localhost 49217 162.255.119.195 443 SYN_SENT
- WINWORD.EXE 172 TCP localhost 49218 167.71.13.65 443 ESTABLISHED
- wscript.exe 2212 TCP localhost 49219 67.207.93.17 7744 SYN_SENT
- java.exe 2204 TCP localhost 49222 localhost 7777 SYN_SENT
- javaw.exe 1724 TCP localhost 49221 185.244.31.111 7788 SYN_SENT
- wscript.exe 2212 TCP localhost 49219 67.207.93.17 7744 SYN_SENT
- javaw.exe 1724 TCP localhost 49240 192.169.69.25 7788 SYN_SENT
- wscript.exe 2212 TCP localhost 49230 67.207.93.17 7744 SYN_SENT
- proc
- --------------
- "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde
- "C:\Program Files\Java\jre1.8.0_131\bin\javaw.exe" -jar "C:\tmp\nloa9qbv.jar"
- wscript C:\Users\operator\ddmwgktkuz.js
- "C:\Windows\System32\WScript.exe" "C:\Users\operator\AppData\Roaming\CgvxwvYwsG.js"
- "C:\Program Files\Java\jre1.8.0_131\bin\javaw.exe" -jar "C:\Users\operator\AppData\Roaming\sutnspffgo.txt"
- "C:\Program Files\Java\jre1.8.0_131\bin\java.exe" -jar C:\tmp\_0.66710452046253931060377835662046911.class
- C:\Windows\system32\xcopy.exe xcopy "C:\Program Files\Java\jre1.8.0_131" "C:\Users\operator\AppData\Roaming\Oracle\" /e
- C:\Windows\system32\reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "ULnOQSoPZLF N" /t REG_EXPAND_SZ /d "\"C:\Users\operator\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\operator\KODhCgcEnMlN\tHIhwWDFSUNOB.eiZoGwJ\"" /f
- C:\Windows\system32\attrib.exe attrib +h "C:\Users\operator\KODhCgcEnMlN\*.*"
- C:\Windows\system32\attrib.exe attrib +h "C:\Users\operator\KODhCgcEnMlN"
- C:\Users\operator\AppData\Roaming\Oracle\bin\javaw.exe -jar C:\Users\operator\KODhCgcEnMlN\tHIhwWDFSUNOB.eiZoGwJ
- C:\Windows\system32\icacls.exe icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage\a2160c77c17b5611.timestamp /grant "everyone":(OI)(CI)M
- C:\Users\operator\AppData\Roaming\Oracle\bin\java.exe -jar C:\tmp\_0.53037232544445945746878749339271613.class
- . . .
- persist
- --------------
- @HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 05.08.2019 18:06
- CgvxwvYwsG c:\users\operator\appdata\roaming\cgvxwvywsg.js 05.08.2019 18:06
- wscript.exe //B "C:\Users\operator\AppData\Roaming\CgvxwvYwsG.js"
- ULnOQSoPZLF N Java(TM) Platform SE binary Oracle Corporation c:\users\operator\appdata\roaming\oracle\bin\javaw.exe 15.03.2017 11:32
- "C:\Users\operator\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\operator\KODhCgcEnMlN\tHIhwWDFSUNOB.eiZoGwJ"
- @C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 05.08.2019 18:06
- CgvxwvYwsG.js c:\users\operator\appdata\roaming\microsoft\windows\start menu\programs\startup\cgvxwvywsg.js 05.08.2019 18:06
- drop
- --------------
- %temp%\nloa9qbv.jar [umucry[1].jar]
- C:\Users\operator\AppData\Roaming\CgvxwvYwsG.js
- C:\Users\operator\AppData\Roaming\sutnspffgo.txt
- C:\Users\operator\AppData\Roaming\Oracle\bin
- C:\Users\operator\fUTkALeaTxM
- C:\Users\operator\KODhCgcEnMlN\tHIhwWDFSUNOB.eiZoGwJ [jar]
- C:\Users\operator\ddmwgktkuz.js
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CgvxwvYwsG.js
- # # #
- https://www.virustotal.com/gui/file/ec845d4c57715e83a80467cfce273e3c54c89aca5229e3f2476057e234c1c0bd/details
- https://www.virustotal.com/gui/file/a104db76b0b3b8387674918217806325a9db2cf0951e9ec9f88ff6a80d9585b7/details
- VR
- @
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement