Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: EMOTET
- CYBERCHEF RECIPE TO GET URLS FROM THE BASE64-ENCODED POWERSHELL SCRIPT
- ----------------------------------------------------------------------
- From_Base64('A-Za-z0-9+/=',true)
- Decode_text('UTF-16LE (1200)')
- Split('*','\\n')
- Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'`'},'',true,false,true,false)
- Find_/_Replace({'option':'Simple string','string':'=Y3nkOs'},' ',true,false,true,false)
- Split('@','\\n')
- Find_/_Replace({'option':'Simple string','string':']b2[s'},'http',true,false,true,false)
- Extract_URLs(false)
- SENDERS OBSERVED
- absolutethaicic@seacuisine.com.my
- admin@talleresinco.arnetbiz.com.ar
- alibaba.credit@hwaidakhotels.com
- asistente.contabilidad2@mineracruz.cl
- barbara@mfsgroup.co.zw
- compras@agroconsulta.com
- hcj92@ms59.hinet.net
- info@dmengineers.co.in
- invoices@carhubjapan.com
- jetro_vicente@dt-factory.com
- jpolmedo@olmedoguerra.com.ar
- kamranaslam@fm91.com.pk
- mehmetpolat@onpo.com.tr
- muhasebe@zumrutparfumeri.com.tr
- naveed.waheed@dadabhoy.edu.pk
- pchomba@staffingafrica.com
- presidente@faa.net
- reception@amazonfoods.ae
- recursos_humanos@bluefinrental.net
- sabeen@rijafashions.com
- sales@mediamerit.com.ph
- umit@zagros-group.com
- vmartha@zopone.com.br
- MALDOC DISTRIBUTION URLS
- http://30sheji.com/ALFA_DATA/ViNCY1lJ3Wnwjp7iGerObGnPkBH7axELaW6e49gAQBIlTsTiOoaj7v4uwvBU/
- http://acepublicidad.com.mx/forms/Z6NCjUY9hyMtZ/
- http://agentsambal.com/wp-admin/re2uGmuFzSMStzTiivGffiPkwulC22u0Xs36dl9Ahap9w7nVZC9EC3z/
- http://anurontv.com/wp-admin/T9zcOGl3UoIksQvCU2kFbBeeutS8lYnG1odLOk7VaSnft1Hwu2J37yLhshRtesY4lj5u/
- http://axocollege.com/jobs/qfeLlmh8N/
- http://bethapro.com/cgi-bin/DEfcw7LCaU6TXyvBmBb0YLWSCPfBazlgdinj/
- http://bsangels.com/tommy-boy-wteclu/mIokEGHGmfhO6oH5rM4PSgsLLqUGkHXY8XstOvGiLxBdFNkDgW969cL/
- http://calgaryautorepairservice.com/wp-content/OV7CVUSdoDpQ95HG0/
- http://cashcart.loan/mikes-bikes-laupj/kmst5YJfkMSBb/
- http://dreamsmattress.in/wordpress/pWZV2PoAbLoa886MvQFjwwmkYLU8e2jd6SE2g4pcY35uiYuy5TSyXnvH/
- http://drpamelageorge.com/wp-includes/1zILg/
- http://eixoarquitetura.com.br/content/6ITRO/
- http://harperwoods-001-site3.btempurl.com/content/bwuy14tezn92b/
- http://hoofdynamics.com/beretta-m9-eumks/zKIU2WU4uZGXJRnLr6Ya2pHkpeWs5yHsPRt4Raz/
- http://jdkems.com/admin/LEWwG4e970Smxq2cR6VIE49uwIkoHTBoNTkO5O4n40GqGE9xKgjgZMOUycZ05aB/
- http://junzhizaixian.com/admin/I9OlacXPqGUPd1RaJC7phteelqqu8hMA3NTQNgZUD1TTRreA2x30sOitTBrRk3EsUtgiA/
- http://lab.lesh.vn/wp-content/QrOs7dmvQPcqPnViFlSsrQHScPc3fTCT3O5/
- http://larayochoaclinicadental.com/wp-content/y41qCdCSc5KtcpsqYcKixnwlP8wbqCaD64uJswo4Da5QKttWpbPMFpTfUNqAs/
- http://localvocal.com/images/xJBgYvtEu6I6s4NPxMziXTExJTWcbu8EYKl08yLMcZRf9GDrgtk1X3YMGt2/
- http://lukelive.in/dolphin-android-heoth/h7c6d22eiVg7E2SNsrhGDnFgJMbRWXqBd/
- http://mahaluxmioil.com/content/WfvHvzOsbX5A4np/
- http://manayradio.com/wp-admin/UyOxy8RA4wpudn/
- http://matadorfashions.com/dimply/RPRNqXyPA3HuAtv/
- http://pageshare.net/sales/9LPvv3NJjJdxeSwMiFWUUen6VJyq8rBu5DEgmhUKI19ePRSVBrtahSkU1ZO7/
- http://priyabeatus.com/iltfjz/lBRkydp3EF3GhZjOStty1gZU7kMVHZIxPmv/
- http://rubisasphalt.com/wp-includes/MxpRRPiCi6UvDMccFpj/
- http://sambalmeletup.com/wp-includes/f8PFVlR7WyLU5MEJbp7kNMc0eUz6o7NR098XOQhSeuPjNWeHm60MYcLl8eeDLKw1seuX/
- http://sancydubai.com/setupconfigo/Xx6cxNI29GeYoT/
- http://shop.symplyfabrics.com/wp-includes/2DhvKotF1GjDJWWKRi9SiBZJKgxGufqwykSyqplh22lD2Qf0kM5tjOFK5saAiiW8KcREH/
- http://uduakcharlesdiaries.com.ng/x99-xeon-ubgpi/pyOXS6Wp0pHC0NKhZg0NJwUOnhURnbwF89MDFjXWrkNOsyVC/
- http://vidyabhartiekalvidyalya.com/ekalvidyalya/XlGhnk9RoNQ98nYU8jhQWasvDWO/
- http://www.68yuanzhijia.xyz/wp-admin/y2kBcwLEzlkonTYMosCer2GGetZbJqXb0OYBIcPckGbOAgXR7T/
- http://www.acepublicidad.com.mx/forms/Z6NCjUY9hyMtZ/
- http://www.alphasierra.wp.appswind.com/v/N3qQqHqvUyPh2DuuVRsDWWAAfT0WiKN29tRd/
- http://www.christopherenovation.fr/unagility/irrlR5vbltSovMvrifV/
- https://ancorals.com/aminophenol/1Levh8/
- https://eytsoft.com/css/ix8JmyjwQW/
- https://game.vlexor.com/links14/MGoIEcpcszYz24ISTMsHzvtbZhTvhIR1WaFqJZ4zoMP8GGn9Mapk3CSfMmxLf3Ds68g/
- https://goldilockstraining.com/wp-includes/ZZ7JwKoL9HwxVJRmE6jZRb7jovAws3GL8V2yV4eX025ND6/
- https://imoblarimoveis.com.br/free-true-e1m7u/RQXBKlswicrhFCbBBvzPnZRfL6dJbL/
- https://infraheroes.ir/wp-includes/aENaHtyk5BzklYrfdbeiDwHlzlLj2fJEzrFVppNxgH67Ee13u0GHKVkBWMRIPf/
- https://jada.co.in/z/UkST/
- https://musickidsprogram.com/wp-includes/KB6YYfwoIjLsh8LVuKXcjPSn/
- https://thehopstopsd.com/pament/iqtFEGuzD4p6YdXTJ6eFOEzReUAECB8D0l0myVM/
- https://tonyzhuangxiu.com/suzanne-morphew-lkgid/wiVWiyPprSGCsTH64zBkaBUtJJd6DQHYHwGm2HPcXs0tn9mc/
- https://www.doodahlabs.com/wp-includes/iCsY1il8/
- 30sheji.com
- 68yuanzhijia.xyz
- acepublicidad.com.mx
- agentsambal.com
- ancorals.com
- anurontv.com
- appswind.com
- axocollege.com
- bethapro.com
- bsangels.com
- btempurl.com
- calgaryautorepairservice.com
- cashcart.loan
- christopherenovation.fr
- doodahlabs.com
- dreamsmattress.in
- drpamelageorge.com
- eixoarquitetura.com.br
- eytsoft.com
- goldilockstraining.com
- hoofdynamics.com
- imoblarimoveis.com.br
- infraheroes.ir
- jada.co.in
- jdkems.com
- junzhizaixian.com
- larayochoaclinicadental.com
- lesh.vn
- localvocal.com
- lukelive.in
- mahaluxmioil.com
- manayradio.com
- matadorfashions.com
- musickidsprogram.com
- pageshare.net
- priyabeatus.com
- rubisasphalt.com
- sambalmeletup.com
- sancydubai.com
- symplyfabrics.com
- thehopstopsd.com
- tonyzhuangxiu.com
- uduakcharlesdiaries.com.ng
- vidyabhartiekalvidyalya.com
- vlexor.com
- DOCUMENT FILE HASHES
- 11f0e6d911676be87bb5b43d33c94717
- 1b9d0443c552a24de0491c0affe0ad22
- 3e55d0d2e89383defa49e63601783a5c
- 594990cb777d1137e638122e9236b834
- 7158ec27841dba17b545e32014ca27a6
- 73be14213d2f6435d2895cd97fd98e4b
- 9bd2b768124a1d27248c333901d70491
- b43b3fa97f354aba4843216837dae788
- cb26af77968809fd82ee154f856d8265
- edc82c608885dd3270635572cb306923
- f09ce175d19406185b1c8fc39f219dee
- f49557e295c2fd54a94cbbcd96c5e6f7
- fca5166cd1205a42369532d545fb9e26
- PAYLOAD FILE HASHES
- 149c4e3a234892e587b1f7c84fdfd05e
- 215e89d759deb72118af11350b436e32
- 4628a82818e759641babda304c0939d2
- 806a8f90d43d2300a9f16a2d1c296f95
- df44443e58657effc0b7f0453db582d2
- e2d23db6cb34e903d89dc85afc32d7ee
- EMOTET PAYLOAD URLs
- http://andeanreach.com/MSInfo/
- http://dupuisacademy.com/projects/media/Me6bB/
- http://gadgetbay.com/letsdeal/7o/
- http://hightimesmarketingandconsulting.com/prediksi-jitu-15vfp/Vr8B/
- http://indemnity360.com/nsw-highways-yqgdk/j63BIy/
- http://karsonhomecare.com/wp-includes/Yo/
- http://new.icfcfilm.com/wp-content/2jMJEJD/
- http://penambahberatbadan.info/x/inf/
- http://siitav.net/cuim/data/2/
- http://tools.apecsoft.asia/application/O/
- http://www.savedahorses.org/wp-content/xH/
- https://alabamaballdrop.com/wp-includes/kef1U/
- https://cashyinvestment.org/wp-content/IH/
- https://coastlinepoolspa.com/wp-content/S88uK/
- https://countrynavigator.com/J/
- https://dr-yasser.com/wordpress/JNS/
- https://praticideas.net/wp-content/inf/
- https://qualcommmedia.com/wp-includes-old/rW1/
- https://secretmassageclub.co.uk/wp-includes/inf/
- https://travianbot.net/wp-admin/R7/
- alabamaballdrop.com
- andeanreach.com
- apecsoft.asia
- cashyinvestment.org
- coastlinepoolspa.com
- countrynavigator.com
- dr-yasser.com
- dupuisacademy.com
- gadgetbay.com
- hightimesmarketingandconsulting.com
- icfcfilm.com
- indemnity360.com
- karsonhomecare.com
- penambahberatbadan.info
- praticideas.net
- qualcommmedia.com
- savedahorses.org
- secretmassageclub.co.uk
- siitav.net
- travianbot.net
- EMOTET C2s
- http://98.109.133.80
- http://75.177.207.146
- http://50.116.111.59:8080
- http://173.249.20.233:443
- http://188.165.214.98:8080
- http://181.165.68.127
- http://110.145.101.66:443
- http://74.208.45.104:8080
- http://118.83.154.64:443
- http://104.131.11.150:443
- http://72.188.173.74
- http://110.145.11.73
- http://78.189.148.42
- http://201.241.127.190
- http://85.105.111.166
- http://174.118.202.24:443
- http://72.186.136.247:443
- http://202.141.243.254:443
- http://185.201.9.197:8080
- http://139.99.158.11:443
- http://79.137.83.50:443
- http://109.116.245.80
- http://87.106.139.101:8080
- http://97.120.3.198
- http://41.185.28.84:8080
- http://190.240.194.77:443
- http://5.39.91.110:7080
- http://138.68.87.218:443
- http://78.188.225.105
- http://119.59.116.21:8080
- http://61.19.246.238:443
- http://167.114.153.111:8080
- http://194.4.58.192:7080
- http://115.94.207.99:443
- http://37.139.21.175:8080
- http://142.112.10.95:20
- http://173.70.61.180
- http://89.216.122.92
- http://100.37.240.62
- http://24.178.90.49
- http://172.105.13.66:443
- http://95.213.236.64:8080
- http://62.30.7.67:443
- http://50.91.114.38
- http://95.9.5.93
- http://152.170.205.73
- http://136.244.110.184:8080
- http://74.128.121.17
- http://120.150.218.241:443
- http://72.229.97.235
- http://190.162.215.233
- http://161.0.153.60
- http://94.23.237.171:443
- http://78.24.219.147:8080
- http://220.245.198.194
- http://46.105.131.79:8080
- http://197.211.245.21
- http://50.245.107.73:443
- http://217.20.166.178:7080
- http://70.183.211.3
- http://202.134.4.211:8080
- http://172.125.40.123
- http://144.217.7.207:7080
- http://190.29.166.0
- http://134.209.144.106:443
- http://194.190.67.75
- http://201.252.34.3
- http://178.152.87.96
- http://47.144.21.37
- http://2.58.16.89:8080
- http://168.235.67.138:7080
- http://203.153.216.189:7080
- http://185.94.252.104:443
- http://58.1.242.115
- http://187.161.206.24
- http://5.2.212.254
- http://172.86.188.251:8080
- http://24.69.65.8:8080
- http://202.134.4.216:8080
- http://64.207.182.168:8080
- http://59.21.235.119
- http://24.179.13.119
- http://51.89.36.180:443
- http://110.145.77.103
- http://109.74.5.95:8080
- http://121.124.124.40:7080
- http://37.187.72.193:8080
- http://172.104.97.173:8080
- http://70.180.33.202
- http://188.219.31.12
- http://62.171.142.179:8080
- http://62.75.141.82
- http://74.40.205.197:443
- http://200.116.145.225:443
- http://139.162.60.124:8080
- http://139.59.60.244:8080
- http://181.171.209.241:443
- http://209.141.54.221:7080
- http://67.170.250.203:443
- http://157.245.99.39:8080
- http://70.92.118.112
- http://120.150.60.189
- http://176.111.60.55:8080
- http://123.176.25.234
- http://49.205.182.134
Add Comment
Please, Sign In to add comment