Advertisement
pastehaste

ORACLE THEMED MALSPAM CAMPAIGN (CVE-2017-11882)

Jan 25th, 2018
489
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.24 KB | None | 0 0
  1. ***ORACLE THEMED MALSPAM CAMPAIGN (CVE-2017-11882)***
  2.  
  3. NOTE:
  4. Distribution method & targeting currently unknown, sample ID'ed via HA
  5.  
  6. RTF DISTRIBUTION:
  7. http://oracle-russia.info/Oracle_RDBMS.rtf
  8. (109.236.89.194)
  9.  
  10. DOC DELIVERED :
  11. Oracle_RDBMS.rtf
  12. a7ed424cf7c78e31bfbd0915b841c6e2
  13. c0026bd9402185eec8a1c7ef5639684a7ae0cd56112b23012225d6f07b5ff866
  14.  
  15. OLE OBJECT 0:
  16. GhfG.py
  17. fc08285173975a38e9be791036f03126
  18. 548f8671d13486bf1c51ea62f85ac5a6d110def6c1bd44bf8e821eeb0a94b08b
  19.  
  20. OLE OBJECT 1:
  21. cmd /c powershell - < %tmp%\GhfG.py
  22.  
  23. DECODED PE FROM PS1:
  24. Akt_sverki_2017.scr
  25. 74b113e6fae947fe9ced001432d6f152
  26. 391038713033ad9d90f32cc0f2680f62c362e369bba32fdf6009dccaa4bc6fa7
  27.  
  28. PE ASSOCIATED URLS:
  29. http://oracle-russia.info/Akt_sverki_2017.scr
  30.  
  31. C2:
  32. teredo-update.com
  33. (185.68.93.26)
  34.  
  35. LETSENCRYPT CERT FINGERPRINT:
  36. 15:f3:5e:c9:d3:10:25:c2:37:47:85:55:d6:bc:2c:01:95:71:d1:b5
  37.  
  38. REFS:
  39. -RTF
  40. https://www.hybrid-analysis.com/sample/c0026bd9402185eec8a1c7ef5639684a7ae0cd56112b23012225d6f07b5ff866?environmentId=120
  41.  
  42. -PS1
  43. https://www.virustotal.com/#/file/548f8671d13486bf1c51ea62f85ac5a6d110def6c1bd44bf8e821eeb0a94b08b/community
  44.  
  45. -EXE
  46. https://www.hybrid-analysis.com/sample/391038713033ad9d90f32cc0f2680f62c362e369bba32fdf6009dccaa4bc6fa7?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement