Advertisement
VRad

#tvrat_210824

Aug 23rd, 2024 (edited)
156
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.96 KB | None | 0 0
  1. #IOC #OptiData #VR #DBatLoader #TeamSpy #TVRAT #teamviewer #rat
  2.  
  3. https://pastebin.com/qJJ0FP7N
  4.  
  5. previous_contact:
  6. 01/02/19 https://pastebin.com/mxZdTDsp
  7.  
  8. FAQ:
  9. https://malpedia.caad.fkie.fraunhofer.de/details/win.dbatloader
  10. https://malpedia.caad.fkie.fraunhofer.de/details/win.teamspy
  11.  
  12. attack_vector
  13. --------------
  14. email attach .zip > .7z > .rar (multi) > .rar (pwd) > .pdf.exe > .msi > AcroRd.exe > C2
  15.  
  16.  
  17. # # # # # # # #
  18. email_headers
  19. # # # # # # # #
  20. Date: Wed, 21 Aug 2024 14:20:39 +0300
  21. From: Устименко Клавдія Левівна <ukrgas @gmail _com>
  22. Subject: Документи на підпис ТОВ "УКР ГАЗ РЕСУРС" до 01.09.24
  23. Reply-To: "public @cip _gov _ua" <public @cip _gov _ua>
  24. Received: from pizza -ct -smtp -03 _virtualhosting _hk ([45 _121 _199 _161])
  25. Received: from uhm219 _servercolo _hk (unknown [203 _135 _134 _164])
  26. Received: from unknown (HELO WIN -LCETV91VPS6) (test @lbsgroup _com _cn @[193 _33 _153 _88])
  27.  
  28. # # # # # # # #
  29. files
  30. # # # # # # # #
  31. SHA-256 130ea8caec2791391ea4158b72b5780258052aadf2166c4394fcf7fe405dc1f2
  32. File name scan_docs_023747_medoc.zip
  33. File size 10.68 MB (11199366 bytes)
  34.  
  35. SHA-256 b111ea050b12e846fb02f8542e69bc4b2e062bbe97e79fec9e00e62ce0c92323
  36. File name Документи.7z
  37. File size 10.68 MB (11198898 bytes)
  38.  
  39. SHA-256 ecda819c9310673f61be9eba59d57517488131859359378c955ca902014d00a2
  40. File name Документи.part1.rar
  41. File size 4.00 MB (4194304 bytes)
  42.  
  43. SHA-256 860759b71749e09f9bebf0b8148dd7658c902197f34caedb067806f550ed8af2
  44. File name Документи.part2.rar
  45. File size 4.00 MB (4194304 bytes)
  46.  
  47. SHA-256 f721239ef73d2b9b9ee780cc27cf7db18e38c0a76e3943e4ab251843a34f7184
  48. File name Документи.part3.rar
  49. File size 2.49 MB (2612628 bytes)
  50.  
  51. SHA-256 9365d958675a4656eddfcdbed058a006a46d447e3575c2a1f6f5c926c0d89be5
  52. File name Документи.rar
  53. File size 10.21 MB (10708798 bytes)
  54.  
  55. SHA-256 dda723c5cd12c505c74c66391c9cf5cfaf8a7aab5fbaf5d0b8599a3a7650154c
  56. File name scan_9374673_Medoc.pdf.exe
  57. File size 10.27 MB (10771544 bytes)
  58.  
  59. SHA-256 beffe9a402b7721009674866ad773008c90b6af543973abdfb81391af4eb7146
  60. File name AcroRd.exe
  61. File size 8.65 MB (9068720 bytes)
  62.  
  63. # # # # # # # #
  64. activity
  65. # # # # # # # #
  66.  
  67. PL_SCR bitbucket _org/ukgas/medoc/downloads/scan_docs_023747_medoc.zip
  68.  
  69. C2 hostes _su 109 _120 _179 _182
  70.  
  71.  
  72. netwrk
  73. --------------
  74. 185 _40 _77 _118 id _xn --80akicokc0aablc _xn--p1ai 443 TLSv1.2 Client Hello (SNI=id _xn--80akicokc0aablc _xn--p1ai)
  75. 109 _120 _179 _182 hostes _su 80 HTTP GET /65iq/update.php?id=***&stat=*** HTTP/1.1 Mozilla/5.0 (MSIE 10.0)
  76. 188 _72 _76 _15 44444 TCP [TCP Keep-Alive] 51219 → 44444 [ACK] Seq=183 Ack=156 Win=64085 Len=1
  77.  
  78. comp
  79. --------------
  80. AcroRd.exe 185 _40 _77 _118 443
  81. AcroRd.exe 188 _72 _76 _15 44444
  82. AcroRd.exe 109 _120 _179 _182 80
  83. AcroRd.exe 185 _40 _77 _118 443
  84. AcroRd.exe 185 _40 _76 _91 44444
  85.  
  86. proc
  87. --------------
  88. C:\Users\User01\Downloads\files2108_1\5_scan_9374673_Medoc.pdf.exe
  89. C:\Users\User01\AppData\Local\Temp\is-LKIHR.tmp\5_scan_9374673_Medoc.pdf.tmp" /SL5="$F0940,10384029,125952,C:\Users\User01\Downloads\files2108_1\5_scan_9374673_Medoc.pdf.exe
  90. C:\Users\User01\Downloads\files2108_1\5_scan_9374673_Medoc.pdf.exe" /verysilent /password=n3xbi
  91. C:\Users\User01\AppData\Local\Temp\is-7PANK.tmp\5_scan_9374673_Medoc.pdf.tmp" /SL5="$100940,10384029,125952,C:\Users\User01\Downloads\files2108_1\5_scan_9374673_Medoc.pdf.exe" /verysilent /password=n3xbi
  92. C:\Windows\SysWOW64\msiexec.exe -i "C:\Users\User01\AppData\Local\Temp\is-KFMTQ.tmp\Acrobat.msi" -qn
  93.  
  94. {another context}
  95.  
  96. C:\Windows\system32\msiexec.exe /V
  97. C:\Windows\syswow64\MsiExec.exe -Embedding 84F4EC5730D3832467AB82B5DADF316C
  98. "C:\Users\User01\AppData\Local\Programs\Acrobat\Reader\AcroRd.exe"
  99.  
  100. persist
  101. --------------
  102. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce Thu Aug 22 20:11:59 2024
  103. Adobe Ассистент 5 (Verified) SAFIB LLC C:\Users\User01\AppData\Local\Programs\Acrobat\Reader\AcroRd.exe Mon Jul 31 16:02:32 2023
  104.  
  105.  
  106. drop
  107. --------------
  108. \Users\User01\AppData\Local\Programs\Acrobat\Reader\AcroRd.exe
  109.  
  110. # # # # # # # #
  111. additional info
  112. # # # # # # # #
  113. msi /password=n3xbi
  114.  
  115. [config]
  116. AccessRules.DeviceLink&0
  117. tmpUserAccessRules.DeviceLink&0
  118. Main.Autorun&1
  119. Main.CloseButtonOperation&0
  120. Main.CheckUpdates&0
  121. Security.UseLocalSecuritySettings&0
  122. Security.DynPassKind&0
  123. Security.PassLifetime&0
  124. Security.CanWinAuth&1
  125. Security.AccessKind&1
  126. Security.CanWinLoginAnotherUser&1
  127. Security.CanWinLoginNotAdmin&1
  128. Security.DenyRemoteSettingsControl&0
  129. Security.DenyLockControls&0
  130. Security.UNCONTROLLED_ACCESS&1
  131. Log.ServerStoreTechLog&0
  132. Main.AWAYMODE_REQUIRED&1
  133. Main.LogsLifetime&1
  134. Main.LogsForMail2Support&1
  135. ProxySettings.UseKind&1
  136. ProxySettings.StoreUserAndPassw&1
  137.  
  138. # # # # # # # #
  139. VT & Intezer
  140. # # # # # # # #
  141. https://www.virustotal.com/gui/url/a83b94d462c54967e0d3c7b78bc92c97a176b87376ee6b084515df2309aec55b/details
  142. https://www.virustotal.com/gui/file/130ea8caec2791391ea4158b72b5780258052aadf2166c4394fcf7fe405dc1f2/details
  143. https://www.virustotal.com/gui/file/b111ea050b12e846fb02f8542e69bc4b2e062bbe97e79fec9e00e62ce0c92323/details
  144. https://www.virustotal.com/gui/file/ecda819c9310673f61be9eba59d57517488131859359378c955ca902014d00a2/details
  145. https://www.virustotal.com/gui/file/860759b71749e09f9bebf0b8148dd7658c902197f34caedb067806f550ed8af2/details
  146. https://www.virustotal.com/gui/file/f721239ef73d2b9b9ee780cc27cf7db18e38c0a76e3943e4ab251843a34f7184/details
  147. https://www.virustotal.com/gui/file/9365d958675a4656eddfcdbed058a006a46d447e3575c2a1f6f5c926c0d89be5/details
  148. https://www.virustotal.com/gui/file/dda723c5cd12c505c74c66391c9cf5cfaf8a7aab5fbaf5d0b8599a3a7650154c/details
  149. https://www.virustotal.com/gui/file/beffe9a402b7721009674866ad773008c90b6af543973abdfb81391af4eb7146/details
  150.  
  151. VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement