Bank_Security

Independence Day greeting campaign delivers Emotet

Jul 10th, 2018
1,016
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.46 KB | None | 0 0
  1. IOCs
  2.  
  3. Download attachment URLs:
  4.  
  5. www.dokassessoria[.]com.br/independence-day/
  6. www.xiaoguoyx[.]com/4th-july/
  7. pds[.]org.pl/independence-day-greetings/
  8. www.acqi[.]cl/independence-day-greetings/
  9.  
  10. Malicious document MD5s:
  11.  
  12. 88b9cff1d3c253f93c56c1a3a3c78800
  13. 3fe87f1b847a8a10989342fb9a92e7c9
  14. 223c733af5b6036d855c7c9177116ef4
  15. 229e78f0da36f6ad099d6fc35f154a5d
  16. 6c0c7ee1f783a1465d1fcad1b227aa43
  17. 57fc905430afb5323c68e14f28e02f4c
  18. 12e13776e95851ebf61e57e0600dfb4f
  19.  
  20. Emotet domain:
  21.  
  22. dessertcake[.]com.ua/he4f
  23. ky663[.]com/zzd
  24. hunter-kings[.]com/wp-content/czVbGb
  25. dotlenieni[.]pl/Fk5j
  26. clubvolvoitalia[.]it/r3z6
  27. ecuadoresort[.]com/Oa
  28. beraysenbas[.]com/hs2Jv5Y
  29.  
  30. Emotet executable MD5s:
  31.  
  32. 27e90f2bc9a214b36a59e4ca0b18e75e
  33. D620a9a598f8848c05f72b025f01289b
  34. Ed0abac215c27665005271cfbf77c027
  35. 9295c23c16cb8615e4349830df30cc12
  36. c0ebf36bb0f204bd76cb33e7d6e50678
  37.  
  38. Emotet C&C
  39.  
  40. 92.27.116.104
  41. 24.173.127.246
  42. 24.121.176.48
  43. 186.71.61.90
  44. 45.73.1.90
  45. 24.234.175.215
  46. 24.119.116.230
  47. 121.50.43.110
  48. 149.62.173.247
  49. 12.182.146.226
  50. 24.229.49.37
  51. 68.2.97.91
  52. 216.21.168.27
  53. 46.105.131.69
  54. 99.224.5.162
  55. 69.17.170.58
  56. 199.119.78.9
  57. 24.74.74.183
  58. 157.7.164.23
  59. 178.21.113.145
  60. 187.178.17.209
  61. 118.244.214.210
  62. 187.156.24.43
  63. 108.170.54.171
  64. 177.99.167.185
  65. 203.201.60.206
  66. 72.0.255.155
  67. 194.88.246.242
  68. 80.153.201.243
  69. 27.50.89.209
  70. 206.210.104.194
  71. 222.214.218.192
  72. 76.72.225.30
  73. 203.45.184.52
  74. 70.182.77.184
  75. 71.244.60.231
  76. 146.185.170.222
  77. 46.105.131.87
  78. 193.251.43.125
  79. 78.47.182.42
Add Comment
Please, Sign In to add comment