Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- EMOTET November 7, 2017 IOC (The email arrived November 6, 2:40PM -5UTC)
- Document name: "New invoice # 295437879655.doc"
- SHA256: c394d23bc99d403d2613ddc56280a5b4fd5b67e47ab9496d8a5311f03cd4b5ef
- https://www.hybrid-analysis.com/sample/c394d23bc99d403d2613ddc56280a5b4fd5b67e47ab9496d8a5311f03cd4b5ef?environmentId=100
- https://www.virustotal.com/en/file/c394d23bc99d403d2613ddc56280a5b4fd5b67e47ab9496d8a5311f03cd4b5ef/analysis/1510068071/
- Enabling content and editing of the Word Document causes a download of a file called BN.exe
- Payload DL site http://sfiafarms.com/FpKNJTj/
- SHA256: e6078f0c13b61558f71186b2e6a7c636f8e8f919336e00ac412eb1f5c2536a73
- https://www.virustotal.com/en/file/e6078f0c13b61558f71186b2e6a7c636f8e8f919336e00ac412eb1f5c2536a73/analysis/1510070334/
- https://www.hybrid-analysis.com/sample/e6078f0c13b61558f71186b2e6a7c636f8e8f919336e00ac412eb1f5c2536a73?environmentId=100
- Post attempted to
- http://77.220.64.43:443/
- http://104.227.137.35:443/
- http://5.9.150.103:443/
- http://148.251.33.195:8080/
- http://206.214.220.81:8080/
- http://167.114.98.61:8080/
- http://217.13.106.16:8080/
- http://69.43.168.234:443/
- http://204.16.201.116/
- http://104.227.137.43:443/
- http://69.43.168.234:443/
- http://5.230.156.95:443/
- http://199.119.78.54:443/
- http://194.88.246.242:443/
- http://207.58.168.91:8080/
- http://217.13.106.249:8080/
- Additional links to pull down the infected Word document that would be in phishing emails
- http://apnatvweb.com/Invoice-due-number-8493697/
- http://biology.fst.unair.ac.id/New-invoice-038249/
- http://gas-global.com/Invoice-1680/
- http://ortakgelecekliderleri.com/scan-094607278/
- http://pripoi31.ru/Invoice-due-number-2416514/
- http://profishtrading.com/Invoice-number-54884-Notification/
- http://snma.fst.unair.ac.id/scan-420564119592/
- http://tekno.fst.unair.ac.id/New-invoice-3784735/
- http://www.ceciestunexercice.fr/Invoice-number-118438/
- http://www.enovakbd.com/Invoice-due-number-02117432/
- https://dynamick.it/NKJTTft0emNUP/
- museeduvieuxlacaune.fr/scan-3620900332/
- thecreativefirm.net/07210457/
- www.look30again.biz/Invoice-number-5723426/
- http://markpolak.com/Payment-with-a-new-address/
- Email content
- Hi LastName, FirstName,
- Couldn’t reach over your phone number for some reason. Need to know the status of this invoice, please reply asap.
- http://pripoi31.ru/Invoice-due-number-2416514/
- Respectfully Yours,
- LastName, FirstName (someone you likely know)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement