Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #icedid #BokBot #DLL
- https://pastebin.com/vYVtngdz
- previous_contact:
- 14/04/2022 https://pastebin.com/X4EvL8N6
- 23/03/2022 https://pastebin.com/LaxLgeEz
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.icedid
- attack_vector
- --------------
- email > attach .zip (pwd) > .ISO > mount > .lnk > rundll32.exe \dinhub.dat,init > 143.198.92.88
- # # # # # # # #
- email_headers
- # # # # # # # #
- Return-Path: <Svetlana.Petrenko@artmotor.toyota.ua>
- Received: from artmotor.toyota.ua (artmotor.toyota.ua [193.34.94.10])
- From: Светлана Петренко <Svetlana.Petrenko@artmotor.toyota.ua>
- Subject: RE: FW: АРТМОТОР 35540470
- Date: Sat, 24 Dec 2022 13:44:42 +0000
- Message-ID: <0f870c0ce68748a3b3025068a2cf9d5b@artmotor.toyota.ua>
- x-originating-ip: [194.110.203.62]
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 21b53e84b59e0bc097805f7aa0595dfa68974d38c34f7421d60cb50f33ab1f19
- File name Request_12-23#183.zip [ Zip archive data, at least v2.0 to extract ]
- File size 398.55 KB (408118 bytes)
- SHA-256 f3a9b733cb33c4d257589e70c8d9cf4b5136cb3932bce2ea1b31bc9d5b06a5ae
- File name Request_12-23#183.iso [ malformed ISO ]
- File size 2.13 MB (2228224 bytes)
- SHA-256 001e90f2cbc6bf380154f7bc0f2f24c40d4a00fa26df29ede1520499bc2a5cf1
- File name Scan.lnk [ MS Windows shortcut ]
- File size 3.07 KB (3146 bytes)
- SHA-256 f60b26151606801fa5232c46bf871eafd4d86f8c723572853f61522d48937a59
- File name dinhub.dat [ PE32+ executable for MS Windows (DLL) (console) Mono/.Net assembly ]
- File size 740.43 KB (758202 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR email_attach
- C2 143.198.92.88:80 [trbiriumpa.co]
- netwrk
- --------------
- 143.198.92.88 trbiriumpa.com 80 HTTP GET / HTTP/1.1
- comp
- --------------
- rundll32.exe 2612 143.198.92.88 80 ESTABLISHED
- proc
- --------------
- C:\Windows\System32\rundll32.exe \dinhub.dat,init
- persist
- --------------
- n/a
- drop
- --------------
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/21b53e84b59e0bc097805f7aa0595dfa68974d38c34f7421d60cb50f33ab1f19/details
- https://www.virustotal.com/gui/file/f3a9b733cb33c4d257589e70c8d9cf4b5136cb3932bce2ea1b31bc9d5b06a5ae/details
- https://www.virustotal.com/gui/file/001e90f2cbc6bf380154f7bc0f2f24c40d4a00fa26df29ede1520499bc2a5cf1/details
- https://www.virustotal.com/gui/file/f60b26151606801fa5232c46bf871eafd4d86f8c723572853f61522d48937a59/details
- https://analyze.intezer.com/analyses/b117e4f0-9904-487a-bfa0-444841c2920d/genetic-analysis
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement