VRad

#rurat_2nd_030321

Mar 3rd, 2021 (edited)
440
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.95 KB | None | 0 0
  1. #IOC #OptiData #VR #rurat #RemoteUtilitiesLLC #EXE #UPX
  2.  
  3. https://pastebin.com/vBf6Wyr5
  4.  
  5. previous_contact:
  6.  
  7. 03/03/21 https://pastebin.com/br4Cayaz
  8.  
  9. FAQ:
  10. https://www.remoteutilities.com/download/#
  11.  
  12. attack_vector
  13. --------------
  14. email > attach .zip > .rar > .exe1 (UPX) > exe2 > install > service > 139.28.38.254
  15.  
  16. email_headers
  17. --------------
  18. Received: from mail.mepr.gov.ua (mail.menr.gov.ua [194.183.172.242])
  19. (envelope-from [email protected])
  20. Received: from gmail.com (176.100.167.8) by SERV-MAIL.menr.local (10.11.12.9)
  21. with Microsoft SMTP Server id 14.3.498.0; Wed, 3 Mar 2021 11:05:16 +0200
  22. From: Кравець Олександр Олександрович <[email protected]>
  23. Subject: Електронний запит (довіданий) Терміново!
  24. Date: Wed, 3 Mar 2021 11:05:23 +0200
  25.  
  26. files
  27. --------------
  28. SHA-256 cc9a27c8850105548515009eaef11ab3ac9f9e1d92c6cc31c7b15108ea4e2af1
  29. File name Електронний запит (виправлений).zip [Zip archive data, at least v1.0 to extract]
  30. File size 19.92 MB (20891967 bytes)
  31.  
  32. SHA-256 191f4a04ec57874093089f27220386272ae21ccc33941ee4d6de89a07aab3c5d
  33. File name Електронний запит (виправлений).rar [RAR archive data, v9a, flags: Locked, Solid,]
  34. File size 19.92 MB (20891127 bytes)
  35.  
  36. SHA-256 8c87f97def691e84a88c085c84a03074bdc3d1d193cdcd543f48b7e5173c33f8
  37. File name Електронний запит (виправлений).exe [PE32 executable, UPX 2.90 [LZMA]] ! Signed file, valid signature
  38. File size 20.41 MB (21401200 bytes)
  39.  
  40. SHA-256 7d3a93970631985f561a98d1c20a4f281ca10a15c76d77637de05ffe65204f7e
  41. File name unpack.exe [PE32 executable, BobSoft Mini Delphi]
  42. File size 22.80 MB (23912560 bytes)
  43.  
  44. installed
  45. --------------
  46. SHA-256 256bce94b14c8b34a9267334670662cf02e7ec1506eb7ad520b08ceefe5a990c
  47. File name host.msi [Microsoft Windows Installer] ! Signed file, valid signature
  48. File size 20.49 MB (21487616 bytes)
  49.  
  50. SHA-256 85b67377703bb2b9509d2fb895bb96d2afd42fe2e69f3d6c265f3a5e5c239598
  51. File name rutserv.exe [PE32 executable, BobSoft Mini Delphi] ! Signed file, valid signature
  52. File size 17.39 MB (18236152 bytes)
  53.  
  54. SHA-256 1f54cb5415178dcb7d43c158898aed122e443a2edd15c85f525fce9cad01ae41
  55. File name rfusclient.exe [ PE32 executable ] ! Signed file, valid signature
  56. File size 10.71 MB (11235064 bytes)
  57.  
  58. original_utility (signed, not modified)
  59. --------------
  60. SHA-256 d4d3ef9196b5dac53d1e06d738eb3e529578752bf9e8cfd2900a600d5f10a7e5
  61. File name host7.0.0.1.exe [PE32 executable, UPX 2.90 [LZMA]]
  62. File size 20.41 MB (21397752 bytes)
  63.  
  64. activity
  65. **************
  66. PL_SCR attached exe
  67.  
  68. C2 139.28.38.254
  69.  
  70. netwrk
  71. --------------
  72. tcp.port == 82 || tcp.port == 5652 || tcp.port == 465
  73.  
  74. 139.28.38.254 51183 → 5652 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
  75. 139.28.38.254 51184 → 82 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
  76. 139.28.38.254 51185 → 465 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
  77.  
  78. !previous contact:
  79. tcp.port == 80 || tcp.port == 8080 || tcp.port == 5651
  80.  
  81. comp
  82. --------------
  83. rutserv.exe 3272 TCP 139.28.38.254 82 ESTABLISHED
  84. rutserv.exe 3272 TCP 139.28.38.254 5652 ESTABLISHED
  85. rutserv.exe 3272 TCP 139.28.38.254 465 SYN_SENT
  86.  
  87. proc
  88. --------------
  89. C:\Users\operator\Desktop\Електронний запит (виправлений).exe
  90. C:\Users\operator\Desktop\Електронний запит (виправлений).exe
  91. "C:\Windows\System32\msiexec.exe" /i "C:\Users\support\AppData\Local\Temp\RUT_{E19EF340-B780-42C7-811E-A23FDB7ACC79}\host.msi" /qn
  92.  
  93. [another context]
  94.  
  95. C:\Windows\system32\msiexec.exe /V
  96. C:\Windows\syswow64\MsiExec.exe -Embedding 031534DEB1A1D91B51BB52E296CE2215
  97. "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" -msi_copy "C:\Users\support\AppData\Local\Temp\RUT_{E19EF340-B780-42C7-811E-A23FDB7ACC79}\host.msi"
  98. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /silentinstall
  99. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /firewall
  100. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" /start
  101.  
  102. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -service
  103. C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe
  104. "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray
  105. "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray
  106. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -firewall
  107.  
  108. persist
  109. --------------
  110. HKLM\System\CurrentControlSet\Services 03.03.2021 11:39
  111.  
  112. RManService Allows Remote Utilities users to connect to this machine. Remote Utilities LLC
  113. c:\program files (x86)\remote utilities - host\rutserv.exe 28.02.2021 14:25
  114.  
  115. "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -service
  116.  
  117. drop
  118. --------------
  119. C:\ProgramData\Remote Utilities\msi\70001_{CE1C66C6-55D6-4DAE-98B7-B8C7FE87342D}\host.msi
  120. C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe
  121. C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe
  122.  
  123. # # #
  124. https://www.virustotal.com/gui/file/cc9a27c8850105548515009eaef11ab3ac9f9e1d92c6cc31c7b15108ea4e2af1/details
  125. https://www.virustotal.com/gui/file/191f4a04ec57874093089f27220386272ae21ccc33941ee4d6de89a07aab3c5d/details
  126. https://www.virustotal.com/gui/file/8c87f97def691e84a88c085c84a03074bdc3d1d193cdcd543f48b7e5173c33f8/details
  127. https://www.virustotal.com/gui/file/7d3a93970631985f561a98d1c20a4f281ca10a15c76d77637de05ffe65204f7e/details
  128.  
  129. installed
  130. https://www.virustotal.com/gui/file/256bce94b14c8b34a9267334670662cf02e7ec1506eb7ad520b08ceefe5a990c/details
  131. https://www.virustotal.com/gui/file/85b67377703bb2b9509d2fb895bb96d2afd42fe2e69f3d6c265f3a5e5c239598/details
  132. https://www.virustotal.com/gui/file/1f54cb5415178dcb7d43c158898aed122e443a2edd15c85f525fce9cad01ae41/details
  133.  
  134. original_utility
  135. https://www.virustotal.com/gui/file/d4d3ef9196b5dac53d1e06d738eb3e529578752bf9e8cfd2900a600d5f10a7e5/details
  136.  
  137. VR
Add Comment
Please, Sign In to add comment