ExecuteMalware

2021-01-04 Emotet IOCs

Jan 4th, 2021
5,809
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.46 KB | None | 0 0
  1.  
  2. THREAT ATTRIBUTION: EMOTET
  3.  
  4. CYBERCHEF RECIPE TO GET URLS FROM THE BASE64-ENCODED POWERSHELL SCRIPT
  5. ----------------------------------------------------------------------
  6. From_Base64('A-Za-z0-9+/=',true)
  7. Decode_text('UTF-16LE (1200)')
  8. Split('*','\\n')
  9. Find_/_Replace({'option':'Simple string','string':'\''},'',true,false,true,false)
  10. Find_/_Replace({'option':'Simple string','string':'+'},'',true,false,true,false)
  11. Find_/_Replace({'option':'Simple string','string':'('},'',true,false,true,false)
  12. Find_/_Replace({'option':'Simple string','string':')'},'',true,false,true,false)
  13. Find_/_Replace({'option':'Simple string','string':'`'},'',true,false,true,false)
  14. Split('@','\\n')
  15. Find_/_Replace({'option':'Simple string','string':']anw[3'},'http',true,false,true,false)
  16. Extract_URLs(false)
  17.  
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC DISTRIBUTION URLS
  22. http://3daybookformatting.com/content/SkkAKQ5we3MfiCTxukxFFogd6bqIApw5SzwDV1rWDbF28/
  23. http://adsenpai.com/cgi-bin/4CxWDkDjYqktBBgfLVAn3voiIlpc9/
  24. http://beauty.scriptspapa.com/wp-admin/T7wb/
  25. http://bubbawatsongolf.com/_ARCHIVE/1kkkKgOZ0fekTnDr9Y221yQmAabJ8I5yGEFlTawlU5OuJtZyYlUmm9/
  26. http://caglayansurucukursu.com/wp-content/B2kcxf0B1cpk7aN0YDhGn7I/
  27. http://callidora.ru/wp-admin/NM4HwYIL/
  28. http://congdongthammy.net/wordpress/2lve24lJenlDGAur7e/
  29. http://elboutika.tn/wp-admin/9PuT0ta9Gh19xg7I8ZI2y9ejXp8QD4GPedLKr9P5hxGmdQpnK/
  30. http://fbsupermarket.com.wtchevalier.com/wp-content/omwvV2aR/
  31. http://findcloud.id/wp-includes/8JTmzq3FN6z3OBJBdBCfXrdcZl5H7ZxOaOZzfl2H/
  32. http://goodjobssolutions.com/mayo-clinic-nmk5w/WQDXUGGDH1memfhbzQba7kowTEW24A/
  33. http://grafitishoes.com/zohoverify/zdvDi9Prkpn5qTAtW9gRh36yfpF7p4gVjlz1HJMnsVRw1Wrx9QgF45AANmD0fdLtNrRhu/
  34. http://harmonimedia.com/wp-content/uploads/zuoNvq95YjQedNraEBjDzEMEkOZxzQeyUQ/
  35. http://hefzi-pub.com/wp-content/zFg8uS6h4GYmANcO/
  36. http://intrastack.com/ozaibxye/ZYViehfMD8WoCII01mE8Nv2bPkJOAPEsiW11c/
  37. http://kaycee.rgpwheels.com/system/CKiv7wWcK5Df2oiknJGQrAAWQ69Wy7mU9bahOcgSffp679uPMlrUrfO8JJt5N/
  38. http://klaksona2.net/_dump/BUyy0Zaa4VOb1rf8Ff0ABcgsiggRypyXBLFQAmlRXAG/
  39. http://lorlighting.cn/uMj2P1uePs2MPjOflCwGSh4MvDIV72EUmEZkaUoYDOg0VN3FGpeHTOym0XzQfce6kSQ6/
  40. http://martinas-kunsthandwerk.at/wp-includes/0LymJH0nWlfRZxSUf1holYj4enNHEXMerRI/
  41. http://morsel.co.in/wp-includes/Kdq0FHpp8Btxy001szwBZZhy6Q3GSEMnno7OOv/
  42. http://mrveggy.com/resgatecarrinho/jcWVa69vj8IDsQRCud8h6RNI9Mz17JqsPPJ0DFnlbXZGyMM2GcZ3/
  43. http://nuockhoang.giaodien.vn/music-in-hjdnn/0cjbhwlIqxK3QGURHK/
  44. http://ocblife-group.com/prediksi-terpercaya-4xmli/PaF2Gu5h/
  45. http://onmovie.pl/wp-admin/5ZP1Us/
  46. http://shaileshpatel.in/cgi-bin/1W4dZyW6qqIjF5uXRr9lp552s0RGd0T/
  47. http://sigo.sosteniweb.com/admin/ga2gDU9CjPiyhLS0jxU7yiMTsGist7dzzGgvgdbCaQCrwhB/
  48. http://smsys.in/cgi-bin/C9alXFt6xvnrImCyI55WEjF8Fc1odOfu2isl0/
  49. http://spaeservices.com/zl1-427-mlle3/AQb4y66arRx3nnxzlevjljYl0HR2Xtyn3BBfLMQLbXi/
  50. http://syntaxive.tech/revive/DLYODDTN7DLHeGSfdC6sP6bydhiMG4aDolRWIH/
  51. http://talentztech.com/histioid/r4U3A1T/
  52. http://thebestfikrah.com/wp-admin/uFHm8bj5DyJUbNBkPrJM9cEfEfi25LmwQo1LRGcsKav4/
  53. http://union.jctrip.cn/wp-includes/kv5xqyfsYEYMO0Ql9A0hbRefUSjOpfRhlLXhxZ3JGSBlX/
  54. http://wagnerbandeira.com.br/wp-admin/g2UDscMa7GMbMsCGxhHPxQFj0YE9qGWfbs9UID60mV/
  55. http://web-de-login.de/wp-admin/hRgyS0HxxKmD1FSjsggdpbjl1NWH2uCsanHJMtRovh82it0jTi1dIIDnl5PwlJdxQ/
  56. http://www.envirolyteck.hunterville.org/wp-admin/2lIbqOWuixWQIiTgvOVO04hiibMsIX7cUhGdpuBLj4LJWji3qxz9/
  57. http://yy.xn--czrs0t/wp-includes/byovfmVbhLawsuhN/
  58. https://admegmbh.com/facebook-algorithm-jxjz5/tC2c5TkggcHP3vtlMNm1FA22DdtkSxj4Oitb6f6WBQkHQx2/
  59. https://brobeerburger.inform.md/wp-admin/ioabTsdFY/
  60. https://hostinganddomain.us/wp-includes/SVe6Rh6NTjY5FCOAJeGsVTLYd0cFu/
  61. https://lfsroot.com/wp-content/vDuaOltfgBKAgtIkFzIAOedx07hmI7aWk0f5JjW/
  62. https://mrveggy.com/resgatecarrinho/jcWVa69vj8IDsQRCud8h6RNI9Mz17JqsPPJ0DFnlbXZGyMM2GcZ3/
  63. https://ngoctugroup.com/wp-admin/y3zQQDx9FaYb4xx/
  64. https://perfectscentsbyamy.co.uk/yaxche/ijm0FNY0EgCkVBdspiXG2t770x0gbr3Cp3FjfTJ3q5rgxtTYjGd/
  65. https://www.thegreektaxi.com/wp-content/CQy9ThSoTY/
  66.  
  67. 3daybookformatting.com
  68. admegmbh.com
  69. adsenpai.com
  70. bubbawatsongolf.com
  71. caglayansurucukursu.com
  72. callidora.ru
  73. congdongthammy.net
  74. elboutika.tn
  75. findcloud.id
  76. giaodien.vn
  77. goodjobssolutions.com
  78. grafitishoes.com
  79. harmonimedia.com
  80. hefzi-pub.com
  81. hostinganddomain.us
  82. hunterville.org
  83. inform.md
  84. intrastack.com
  85. jctrip.cn
  86. klaksona2.net
  87. lfsroot.com
  88. lorlighting.cn
  89. martinas-kunsthandwerk.at
  90. morsel.co.in
  91. mrveggy.com
  92. ngoctugroup.com
  93. ocblife-group.com
  94. onmovie.pl
  95. perfectscentsbyamy.co.uk
  96. rgpwheels.com
  97. scriptspapa.com
  98. shaileshpatel.in
  99. smsys.in
  100. sosteniweb.com
  101. spaeservices.com
  102. syntaxive.tech
  103. talentztech.com
  104. thebestfikrah.com
  105. thegreektaxi.com
  106. wagnerbandeira.com.br
  107. web-de-login.de
  108. wtchevalier.com
  109. yy.xn--czrs0t
  110.  
  111. DOCUMENT FILE HASHES
  112. 22e3fc629fb48006853f835c8b6c4973
  113. 32bf288e61b2a0c9585eb2f3ed54f998
  114. b362e5db4a26fe8fa49294d030099882
  115. db74b33012bff06e61271094c65c333f
  116. eca7b443bdd18089d1e72b2394abfd96
  117. faf2165619d1daa46b0d172147a52541
  118.  
  119. PAYLOAD FILE HASHES
  120. 032ed138c32c20af158e583da0aacb22
  121. 0ac3ee201f24fbb1bcc81121929c9971
  122. 0df5383e20f720415a744f99bf5d9b00
  123. 1be626b2f1d92fa9582ff937ede5398d
  124. 1ff0d58dc455a1089ea49c616e47c276
  125. 2ddb796a1cc50f5390b937daa2b708b0
  126. 3313bc5dc53a5a2a9b4010f60e45500c
  127. 509a553e0d37c412056f429f7e096013
  128. 59ea441a0aa63057a10ebb391b855151
  129. 77ee283da5525ccc5840f6dad95d74c1
  130. 8736e7b1eb4afc041c7a0ce4e80ee4b3
  131. 91eb537a28914ec23f119c8b6adba812
  132. bbb571a04c13c74efa27ed0e84d2dda5
  133. d608c6782f2551a3ad9d9863140e6c07
  134. df1d2a755a6b31adfb558f8cfe641c4e
  135. f8fe349d11b06f2724afe155020e5f43
  136.  
  137. EMOTET PAYLOAD URLs
  138. http://anakhita.com/wordpress/Pt/
  139. http://etbnaman.com/wp-admin/V0Sv/
  140. http://etdog.com/wp-content/nu/
  141. http://ezdesigns.net/ALFA_DATA/h/
  142. http://firefightersanta.org/content/1BNtMyv/
  143. http://freelancerwebdesignerhyderabad.com/cgi-bin/S/
  144. http://holonchile.cl/cgi-bin/font/
  145. http://indemnity360.com/nsw-highways-yqgdk/Sys/
  146. http://labasedespatriotes.net/wp-content/tGjE/
  147. http://menol.eu/wp/mT/
  148. http://norailya.com/drupal/n0uJoiR/
  149. http://spovahealth.com/z/Vb/
  150. http://the-ly.com/wp-admin/8/
  151. http://ultimatesoftwarenet.com/wp-content/6rXDH9/
  152. http://wm.mcdevelop.net/content/6F2gd/
  153. http://www.bifangting.com/wp-content/f/
  154. http://www.lapcare.com/wp-content/9fotgty/
  155. http://www.mt4-ea.vip/sys-cache/62y7sA/
  156. http://www.sinclair-electrical.com/wp-includes/np/
  157. http://www.stmarouns.nsw.edu.au/paypal/b8G/
  158. http://yisankeji.site/content/2uPjX/
  159. http://youyouwj.com/b/HW/
  160. https://admintk.com/wp-admin/L/
  161. https://dayimachine.com/automator-mouse-xoq9e/aY9/
  162. https://doctorww.com/22-hp-ak4yp/LRWLZ2/
  163. https://elaheanahita.org/a/sbzLscs/
  164. https://etkindedektiflik.com/pcie-speed/Engines/
  165. https://ibelieveonline.org/wp-content/FvSP7/
  166. https://mikegeerinck.com/c/YYsa/
  167. https://mozzo.app/fitbit-charge-nefsx/oBgnw/
  168. https://praticideas.net/wp-content/en-US/
  169. https://ummahstars.com/app_old_may_2018/assets/Help/
  170. https://whytech.info/wp-includes/oa/
  171. https://www.hintup.com.br/wp-content/dE/
  172.  
  173. admintk.com
  174. anakhita.com
  175. bifangting.com
  176. dayimachine.com
  177. doctorww.com
  178. elaheanahita.org
  179. etbnaman.com
  180. etdog.com
  181. etkindedektiflik.com
  182. ezdesigns.net
  183. firefightersanta.org
  184. freelancerwebdesignerhyderabad.com
  185. hintup.com.br
  186. holonchile.cl
  187. ibelieveonline.org
  188. indemnity360.com
  189. labasedespatriotes.net
  190. lapcare.com
  191. mcdevelop.net
  192. menol.eu
  193. mikegeerinck.com
  194. mozzo.app
  195. mt4-ea.vip
  196. norailya.com
  197. praticideas.net
  198. sinclair-electrical.com
  199. spovahealth.com
  200. stmarouns.nsw.edu.au
  201. the-ly.com
  202. ultimatesoftwarenet.com
  203. ummahstars.com
  204. whytech.info
  205. yisankeji.site
  206. youyouwj.com
  207.  
  208. EMOTET C2s
  209. http://90.160.138.175
  210. http://74.222.117.42
  211. http://157.245.123.197:8080
  212. http://50.116.111.59:8080
  213. http://173.249.20.233:443
  214. http://200.116.145.225:443
  215. http://142.112.10.95:20
  216. http://87.106.139.101:8080
  217. http://173.70.61.180
  218. http://75.177.207.146
  219. http://121.124.124.40:7080
  220. http://98.109.133.80
  221. http://37.187.72.193:8080
  222. http://74.40.205.197:443
  223. http://220.245.198.194
  224. http://197.211.245.21
  225. http://123.176.25.234
  226. http://194.190.67.75
  227. http://78.188.225.105
  228. http://217.20.166.178:7080
  229. http://49.205.182.134
  230. http://79.137.83.50:443
  231. http://50.91.114.38
  232. http://62.171.142.179:8080
  233. http://119.59.116.21:8080
  234. http://75.109.111.18
  235. http://24.179.13.119
  236. http://120.150.60.189
  237. http://24.69.65.8:8080
  238. http://185.201.9.197:8080
  239. http://154.0.8.2:443
  240. http://118.83.154.64:443
  241. http://161.0.153.60
  242. http://61.19.246.238:443
  243. http://100.37.240.62
  244. http://66.57.108.14:443
  245. http://144.217.7.207:7080
  246. http://181.165.68.127
  247. http://174.118.202.24:443
  248. http://188.219.31.12
  249. http://89.106.251.163
  250. http://104.131.11.150:443
  251. http://181.171.209.241:443
  252. http://178.152.87.96
  253. http://89.216.122.92
  254. http://172.125.40.123
  255. http://47.144.21.37
  256. http://185.94.252.104:443
  257. http://139.59.60.244:8080
  258. http://24.231.88.85
  259. http://190.240.194.77:443
  260. http://190.29.166.0
  261. http://194.4.58.192:7080
  262. http://138.68.87.218:443
  263. http://187.161.206.24
  264. http://78.189.148.42
  265. http://74.128.121.17
  266. http://75.188.107.174
  267. http://202.141.243.254:443
  268. http://59.21.235.119
  269. http://62.30.7.67:443
  270. http://5.2.212.254
  271. http://134.209.144.106:443
  272. http://110.145.11.73
  273. http://139.162.60.124:8080
  274. http://95.213.236.64:8080
  275. http://51.89.36.180:443
  276. http://41.185.28.84:8080
  277. http://168.235.67.138:7080
  278. http://203.153.216.189:7080
  279. http://93.146.48.84
  280. http://94.23.237.171:443
  281. http://74.208.45.104:8080
  282. http://5.39.91.110:7080
  283. http://172.105.13.66:443
  284. http://109.74.5.95:8080
  285. http://115.94.207.99:443
  286. http://78.24.219.147:8080
  287. http://70.92.118.112
  288. http://37.139.21.175:8080
  289. http://24.178.90.49
  290. http://62.75.141.82
  291. http://188.165.214.98:8080
  292. http://84.232.252.202:443
  293. http://74.58.215.226
  294. http://109.116.245.80
  295. http://64.207.182.168:8080
  296. http://110.145.101.66:443
  297. http://136.244.110.184:8080
  298. http://202.134.4.216:8080
  299. http://2.58.16.89:8080
  300. http://95.9.5.93
  301. http://172.104.97.173:8080
  302. http://172.86.188.251:8080
  303. http://167.114.153.111:8080
  304. http://176.111.60.55:8080
  305. http://202.134.4.211:8080
  306. http://67.170.250.203:443
  307. http://46.105.131.79:8080
  308. http://70.183.211.3
  309. http://139.99.158.11:443
  310. http://24.164.79.147:8080
  311. http://85.105.111.166
  312. http://157.245.99.39:8080
  313. http://201.241.127.190
  314. http://97.120.3.198
  315. http://50.245.107.73:443
  316.  
  317. http://125.0.215.60
  318. http://163.53.204.180:443
  319. http://89.163.210.141:8080
  320. http://203.157.152.9:7080
  321. http://157.245.145.87:443
  322. http://82.78.179.117:443
  323. http://85.247.144.202
  324. http://37.46.129.215:8080
  325. http://110.37.224.243
  326. http://192.210.217.94:8080
  327. http://2.82.75.215
  328. http://69.159.11.38:443
  329. http://188.166.220.180:7080
  330. http://103.93.220.182
  331. http://198.20.228.9:8080
  332. http://91.75.75.46
  333. http://88.247.30.64
  334. http://189.211.214.19:443
  335. http://203.160.167.243
  336. http://178.33.167.120:8080
  337. http://178.254.36.182:8080
  338. http://70.32.89.105:8080
  339. http://103.80.51.61:8080
  340. http://54.38.143.245:8080
  341. http://113.203.238.130
  342. http://50.116.78.109:8080
  343. http://195.201.56.70:8080
  344. http://109.99.146.210:8080
  345. http://75.127.14.170:8080
  346. http://172.193.14.201
  347. http://203.56.191.129:8080
  348. http://157.7.164.178:8081
  349. http://46.32.229.152:8080
  350. http://78.90.78.210
  351. http://116.202.10.123:8080
  352. http://189.34.18.252:8080
  353. http://114.158.126.84
  354. http://201.193.160.196
  355. http://79.133.6.236:8080
  356. http://202.29.237.113:8080
  357. http://203.153.216.178:7080
  358. http://172.96.190.154:8080
  359. http://74.208.173.91:8080
  360. http://139.59.61.215:443
  361. http://117.2.139.117:443
  362. http://24.230.124.78
  363. http://5.83.32.101
  364. http://139.5.101.203
  365. http://8.4.9.137:8080
  366. http://120.51.34.254
  367. http://188.226.165.170:8080
  368. http://91.83.93.103:443
  369. http://183.91.3.63
  370. http://192.241.220.183:8080
  371. http://190.18.184.113
  372. http://2.58.16.86:8080
  373. http://5.79.70.250:8080
  374. http://113.161.176.235
  375. http://46.105.131.68:8080
  376. http://223.17.215.76
  377. http://186.146.229.172
  378. http://186.96.170.61
  379. http://121.117.147.153:443
  380. http://192.163.221.191:8080
  381. http://139.59.12.63:8080
  382. http://115.79.195.246
  383. http://172.104.46.84:8080
  384. http://180.52.66.193
  385. http://185.208.226.142:8080
  386. http://152.32.75.74:443
  387. http://143.95.101.72:8080
  388. http://47.150.238.196
  389. http://201.212.201.127:8080
  390. http://190.85.46.52:7080
  391. http://182.73.7.59:8080
  392. http://178.62.254.156:8080
  393. http://195.159.28.244:8080
  394. http://103.229.73.17:8080
  395. http://103.124.152.221
  396. http://180.148.4.130:8080
  397. http://60.108.128.186
  398. http://110.172.180.180:8080
  399. http://162.144.145.58:8080
  400. http://37.205.9.252:7080
  401. http://185.142.236.163:443
  402. http://27.78.27.110:443
  403. http://58.27.215.3:8080
  404. http://125.0.215.60
Add Comment
Please, Sign In to add comment