ExecuteMalware

2020-07-17 Emotet IOCs

Jul 17th, 2020
6,909
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.37 KB | None | 0 0
  1. THREAT ATTRIBUTION: EMOTET
  2.  
  3. Dynamic method Used To Get Emotet IOCs:
  4. 1. Disable Internet connectivity
  5. 2. Start CMD Watcher
  6. 3. Open Word documents and grab the base64-encoded Powershell script from CMD Watcher
  7. 4. CyberChef Recipe to decode:
  8. From_Base64('A-Za-z0-9+/=',true)
  9. Decode_text('UTF-16LE (1200)')
  10. Split('*','\\n')
  11. Extract_URLs(false)
  12. 5. Enable internet connectivity and manually download .exe from payload URLs
  13. 6. Disable internet connection again and run one of the payload executables - capture C2 traffic in Fiddler
  14.  
  15.  
  16. SENDERS OBSERVED
  17.  
  18. DOCUMENT FILE HASHES
  19. 1ff452af811663fe1b2d02d818f213e8
  20. 20bd788b3f0682c4f0146ae9a554d54b
  21. 3c9cbc6f2976548609dea56d147b20f1
  22. 6e17f259490bde55e2e751dd2440d33a
  23. 73a75e40d5b73fe35ded2a82b1743cbe
  24. 74c8c361a7a78d096c2dbd629b5abc6d
  25. 780732f1e23e7e09be35e23412dfeecd
  26. 7872817339a35c2452babd1f1cc30d5d
  27. 78fe1505b6851ea884ef555874373ded
  28. 8edc8e6d88636b9e5350aa2e80f8336d
  29. 968203d0531ceb11a0e3298c390c2872
  30. a97740e8d3d27258f8e25de5c1a8e9b4
  31. b270acc8fd391d79b4d0bfac126cc5ff
  32. b97a25f68f9c501c487735d5c058757e
  33. d8641ce9ed475045cf82d82463399ad9
  34. ec9b276d4666d77203b46d89227fe2cd
  35.  
  36. PAYLOAD FILE HASHES
  37. 13067d944a3c16ce092dbe80d3f69b41
  38. 30333d086f47122e8bf43b2ff6076bff
  39. 62f979be778c0d83047350fa2d1de2a1
  40. 759e289fa582cd91f0e2f69e6baff40a
  41. 90c500199a04f70cd810e55c56e01cea
  42. d2916d363b9d9b7f16e8210da16f42bf
  43. ecfc2d4481aaa0dfc8aaaa1fad367f56
  44.  
  45. MALDOC DOWNLOAD URLs
  46. http://aarunya.in/wp-admin/swift/3jc4jqgai3rf/98382623658csjsmcfrnnlx032w6e9/
  47. http://af2play.online/cadic/DOC/q9n256866279950911462178txj81v0getc0nq8d84nl/
  48. http://agoty.org/wp-content/uploads/1569700949_aQmJGB6jChk2g_6711054_esaD78/e0n1mn2x_6ygf_41wR_vLbhodeZ/05uoy_108vytsx7/
  49. http://akzy.top/h8ioc8/Documentation/
  50. http://bushireinlondon.co.uk/fonts/available_disk/test_forum/676747_SYh9NiV2/
  51. http://careco.parts/wp-content/Uf/
  52. http://cellstore.net.br/wp-admin/protected-zone/interior-zgirj9bvpgy5ef1-0z7d5cqgj949/KL4SoBjA0s-nGbvgduN/
  53. http://cepabol.noticias.bo/alfacgiapi/ybaurum4dq/
  54. http://cleardristi.com/cleardristi.com_WP_INSTALL/g84oq8lq9ek_d0qdnl3l0gkrr_module/corporate_wkg55rof6x_cf5kxjphwqyz/who5_06y576/
  55. http://demo.xoweb.cn/static/public/yn4g1lj32bix/
  56. http://drive.medisail.fr/lib/INC/
  57. http://dsoft.software/euy/lj/
  58. http://elilaifs.cn/wp-admin/parts_service/jecxwnaz1j/
  59. http://essah.in/new/jke8sdg-a892-41684/
  60. http://exchangecamp.ir/wp-admin/Documentation/
  61. http://guoxiaorui.cn/wp-admin/private_FbVo_PSouiS1uKbbyfs/interior_forum/9005074_1StXFeoXH8jW9/
  62. http://hirebyprofession.com/assets/lm/
  63. http://linhkien36.cf/wp-admin/personal_array/open_forum/248250499770_SkHduGJkxpK/
  64. http://linhkien36.net.co/wp-admin/browse/
  65. http://longphuong.tk/wp-admin/browse/buz7el/
  66. http://minibus-hire-basingstoke.co.uk/js/erhXjTo/
  67. http://money-crdt.ru/q0by2r/invoice/
  68. http://movie.cxyw.net/fork/LLC/jj0av1ems/xrgxn858627574n193e6s4zoqd2/
  69. http://pasca.fapet.ub.ac.id/l/sites/
  70. http://psotm.pl/wp-includes/closed_zone/interior_area/963338392_kCrsPUBs/
  71. http://ranks.hoonicorns.pt/comp3/Overview/00giwvmzhy/s04054954269w9vtvn5tqlan/
  72. http://sample.tri-comma.com/wp-admin/FILE/
  73. http://stayfitphysio.ca/wp-content/plugins/balance/fzozekbnnb/
  74. http://steelworks-students.com/wp-admin/FILE/ype8vbeho2jn/
  75. http://sul.t.12cotacao.us/clicar/32551467/
  76. http://swingcommerce.com/wp-content/uploads/closed_box/YHim0z_mvqyzrJPRQe_76jy_mxy1me3/pa84uf2f2oqj_sv590sx04s45wy/
  77. http://tangramadigital.tecnologia.bo/wp-admin/87296192280_GCdHQit_473088_QQLl2FZUTJVfNgF/guarded_forum/hfwF5TB7kQ_uLMfnpJjwN63/
  78. http://tarisfotografi.com/aup/Overview/
  79. http://temp.tara.edu.lk/wp-content/uploads/2020/personal-DVdtZjL-mQSSVjj/test-profile/17169653973-18JoYS1FAiHzZCDR/
  80. http://teste.hoonicorns.pt/ddfcn41dj/payment/epwsnm/
  81. http://tophoras.hoonicorns.pt/comp3/z9-9elt-66213/
  82. http://triptovacations.com/wp-content/wadJUaE/
  83. http://ulfhorror.com/wp-admin/83279465106718/7fkhh84265327972167057acuknjrmhrfbxz9bdd/
  84. http://united-vision.net/smart-school-5.0/available_disk/open_space/4648749024_erM9SWF/
  85. http://watkins.mitchellpwright.com/wp-includes/docs/lg2wm6zn/sxhgff291213969722cb2tpmjwffm/
  86. http://web86.s146.goserver.host/hk9jj/CchogvhEi/
  87. http://wmzart.com/wp-includes/available-box/special-area/682477561403-C9hB9Em/
  88. http://www.0931tangfc.com/images/multifunctional_d1hiw_ewtuc2kwj/verifiable_space/2w3z_403y7v5934/
  89. http://www.ajanews.asia/wp/Document/5r65712504026116389jmyzp09zw2b3sfn63/
  90. http://www.aumhealings.org/wp-admin/docs/1izhzmhbo/
  91. http://www.carloni.com.br/wp-includes/closed-module/corporate-090menkn8gyh0v-flesu2z9rvhj/xzus-294v8y/
  92. http://www.dawoodsupermarket.com/wp-admin/eNUOCqw/
  93. http://www.gdstechnologies.co.in/app/eTrac/
  94. http://www.leonardoenergie.it/media/balance/
  95. http://www.mikesar.com/cgi-bin/FILE/9iy3rbp/yc697386432801482480z1o1srx37/
  96. http://www.mikesar.com/cgi-bin/rqag0gz/
  97. http://www.oakeno.com/wp-admin/801579841823_XUeIoA6k4S663_zone/test_area/rgfnwniaa_3x7u49063/
  98. http://www.quintapavicich.com.ar/3e8mgy/private-module/individual-profile/wo718fkda46wwqw-04xs44/
  99. http://www.timelyrain.top/wp-includes/ID3/parts_service/enlbnfk4xl/
  100. http://wx.yuan.fit/data/multifunctional-ni7pt4lu-igevj/interior-profile/6kj-s2ss899y0wtzy/
  101. http://yihe.fcglobal.com.cn/phpsso_server/ej9ni-qb-014/
  102. http://ypbb.or.id/wp-content/bao-5yp-968/
  103. http://yuan.fit/wp-admin/v3na-c7uu-042786/
  104. http://zeing-kor.com/b/common_array/open_12aprkbzsnv01y_4uawa/87933126050098_FOkxEXj/
  105. http://zingadata.com/wp-content/protected-680154094967-NkP2aIaG/guarded-TDUl5Ai-CW9oksOL8Jh/1705605-2vBjnW/
  106. https://1haowan.cn/wp-includes/protected-disk/open-653784029-jIpt1NW/mzWXqM-lk28z57HqL/
  107. https://affutes.netavantage.com/wp-content/closed-9858205266-15AeMiAnE9/open-warehouse/9YpjLKfyXx-lzyNfHLNn/
  108. https://ahdaaf.me/site/attachments/8uawrs20822876186p63anwn63gv9dv/
  109. https://allamanolibrary.com/zyro/public/
  110. https://anikwp.com/6d3jv/personal_box/open_Loa8_MvQFjwwmkY/8064625563_dYBaZNqg0f2/
  111. https://antalyalogodestek.com/wp-content/public/
  112. https://bawaslu.wonosobokab.go.id/wp-content/iskGT/
  113. https://construtoraaguiar.com.br/wp-includes/available-ph1S-smmNI7wAUDV42iB/special-portal/528912442-bGAY3pyBEmP/
  114. https://daniwilkinson.co.uk/dup-installer/sites/3u01718046821pkh6l38v42wa3e1eiw/
  115. https://delhisuppliers.in/wp-admin/closed_array/open_space/gwr2soq_4wy25t3026/
  116. https://dinghaomcc.com/wp-admin/protected-resource/interior-area/lnlnimb-yw16sztu69/
  117. https://doraflob.com/fef2/Document/
  118. https://fitmode.vn/wp-admin/common-09174168043-bWUexpZAf3/guarded-space/xvy4fksg-66xy89524359w/
  119. https://grafikos.com.ar/cgi-bin/open-43667-nqZwUKt5/security-3lrg-AjxU8K4c/12097743559-MsAVhVJHCjVT4bV/
  120. https://hightea.tk/wp-admin/LLC/uxblj70750248131jyb5yjz51vq9r3zg0yo/
  121. https://ideanetsolutions.com/wp-admin/multifunctional-zone/guarded-mglbz8f9qqm-77foumy8y423bo/ZqnWyCb1ePV-yhG1xbpjL/
  122. https://ineedmoney.loan/wp-content/dAXpzb/
  123. https://koncenful.com/wp-content/lm/hmhj52/ook7ri689941810111164mlk5ffuksnm6anf/
  124. https://konipapua.com/wp-content/uploads/
  125. https://konipapua.com/wp-content/uploads/zpqn7d-w8-418/
  126. https://max-hoffmann-webdesign.de/eTrac/
  127. https://momentomt.com.br/wp-includes/5lto7-by5y-45/
  128. https://qhn.vn/default/attachments/
  129. https://qrtalk.nl/wp-content/docs/f6k3vrc0/
  130. https://robotena.org/wp-admin/dhly-qh6p-87788/
  131. https://steer2vision.com/recurringo/Overview/t8oku994412361893ciornz3iuaysczvm/
  132. https://www.chinavok.com/wv7kv/multifunctional-gmgtAcb-XzR6tiFghuo/additional-gN3u1-JPwnriOV0YM/wg7hzo1jit-0sus2x/
  133. https://www.fleuve.tk/wp-admin/statement/zfkdtqgff/
  134. https://www.pharma-israel.org.il/wp-content/DOC/
  135. https://www.strain.ee/site/82kxurzh-4x7-27/
  136. https://www.supercutscissors.com/wp-content/uploads/11a-t48x-5941/
  137. https://www.ziyuan.tech/wp-admin/Documentation/
  138.  
  139. EMOTET PAYLOAD URLs
  140. http://abatiy.com/yaa/po0395/
  141. http://cpads.net/7iuhq/mri/
  142. http://crm.shaayanpharma.com/application/ffltO/
  143. http://fivestarcleanerstx.com/wp-content/mu-plugins/2CLid868/
  144. http://shubhinfoways.com/p/XEcc5x1qx73/
  145. http://sustainableandorganicgarments.com/komentarz/KHF6ry92657/
  146. http://test2.cxyw.net/hyeht3/aWybkzi/
  147. http://topgameus.com/AutoIT_UngdungOnline/zqjqel/
  148. http://www.szhealthshield.com/websiteguide/k82i/
  149. http://zazabajouk.com/cf9r4nd/Xsma350581/
  150. https://aliyousefpoor.com/wp-admin/Gkt8B41139/
  151. https://bhandaraexpress.com/wp-includes/0Iw2jW2/
  152. https://digitalcon7.net/wp-snapshots/0Wn/
  153. https://e2e-solution.com/sandbox/Sv2880/
  154. https://exam.ylsbmeirong.com/data/tjEyH973/
  155. https://fivestarcleanerstx.com/wp-content/mu-plugins/2CLid868/
  156. https://ramukakaonline.com/wp-includes/cxSzmSXN/
  157. https://skenglish.com/wp-admin/o0gf/
  158. https://ssuse.com/wp-content/uploads/IMv2xyEc3/
  159. https://thesuperservice.com/wp-admin/rL00/
  160. https://tyres2c.com/wp-admin/zu2h/
  161. https://www.elseelektrikci.com/wp-content/hedk3/
  162. https://www.packersmoversmohali.com/wp-includes/pgmt4x/
  163. https://www.rviradeals.com/wp-includes/LeDR/
  164. https://www.tri-comma.com/wp-admin/MmD/
  165.  
  166. EMOTET C2s
  167. http://101.187.97.173
  168. http://103.86.49.11:8080
  169. http://104.131.103.37:8080
  170. http://104.131.11.150:443
  171. http://104.131.41.185:8080
  172. http://104.131.44.150:8080
  173. http://104.236.161.64:8080
  174. http://104.236.246.93:8080
  175. http://104.247.221.104:443
  176. http://108.48.41.69
  177. http://109.117.53.230:443
  178. http://109.74.5.95:8080
  179. http://110.143.151.194
  180. http://110.145.77.103
  181. http://111.67.12.221:8080
  182. http://113.160.130.116:8443
  183. http://113.190.254.245
  184. http://114.109.179.60
  185. http://116.203.32.252:8080
  186. http://12.162.84.2:8080
  187. http://121.124.124.40:7080
  188. http://137.59.187.107:8080
  189. http://137.74.106.111:7080
  190. http://139.130.242.43
  191. http://139.59.60.244:8080
  192. http://143.0.87.101
  193. http://149.62.173.247:8080
  194. http://153.126.210.205:7080
  195. http://157.245.99.39:8080
  196. http://162.154.38.103
  197. http://162.241.92.219:8080
  198. http://168.235.67.138:7080
  199. http://169.239.182.217:8080
  200. http://170.81.48.2
  201. http://172.104.169.32:8080
  202. http://173.91.22.41
  203. http://176.111.60.55:8080
  204. http://177.139.131.143:443
  205. http://177.144.135.2
  206. http://177.66.190.130
  207. http://177.72.13.80
  208. http://178.79.163.131:8080
  209. http://181.120.79.227
  210. http://181.129.96.162:8080
  211. http://181.31.211.181
  212. http://185.94.252.104:443
  213. http://185.94.252.12
  214. http://185.94.252.13:443
  215. http://185.94.252.27:443
  216. http://186.208.123.210:443
  217. http://186.250.52.226:8080
  218. http://186.70.127.199:8090
  219. http://187.162.248.237
  220. http://187.51.47.26
  221. http://189.218.165.63
  222. http://190.108.228.62:443
  223. http://190.144.18.198
  224. http://190.147.137.153:443
  225. http://190.160.53.126
  226. http://190.163.1.31:8080
  227. http://190.17.195.202
  228. http://190.181.235.46
  229. http://190.194.242.254:443
  230. http://190.229.148.144
  231. http://190.55.181.54:443
  232. http://190.6.193.152:8080
  233. http://192.241.143.52:8080
  234. http://192.241.146.84:8080
  235. http://2.47.112.152
  236. http://200.41.121.90
  237. http://200.55.243.138:8080
  238. http://201.173.217.124:443
  239. http://201.213.32.59
  240. http://202.62.39.111
  241. http://203.153.216.189:7080
  242. http://203.25.159.3:8080
  243. http://204.225.249.100:7080
  244. http://207.255.37.143
  245. http://209.141.54.221:8080
  246. http://210.165.156.91
  247. http://212.51.142.238:8080
  248. http://212.71.237.140:8080
  249. http://217.13.106.14:8080
  250. http://217.199.160.224:7080
  251. http://219.92.13.25
  252. http://222.214.218.37:4143
  253. http://24.1.189.87:8080
  254. http://31.31.77.83:443
  255. http://37.139.21.175:8080
  256. http://37.187.72.193:8080
  257. http://41.60.200.34
  258. http://45.161.242.102
  259. http://46.105.131.79:8080
  260. http://46.105.131.87
  261. http://46.214.11.172
  262. http://46.28.111.142:7080
  263. http://5.196.35.138:7080
  264. http://5.196.74.210:8080
  265. http://5.39.91.110:7080
  266. http://50.116.86.205:8080
  267. http://50.28.51.143:8080
  268. http://51.255.165.160:8080
  269. http://58.153.68.176
  270. http://60.130.173.117
  271. http://61.19.246.238:443
  272. http://61.92.159.208:8080
  273. http://62.138.26.28:8080
  274. http://62.75.141.82
  275. http://68.183.170.114:8080
  276. http://68.183.190.199:8080
  277. http://70.32.115.157:8080
  278. http://70.32.84.74:8080
  279. http://72.47.248.48:7080
  280. http://73.11.153.178:8080
  281. http://74.208.45.104:8080
  282. http://75.139.38.211
  283. http://77.55.211.77:8080
  284. http://77.90.136.129:8080
  285. http://78.189.165.52:8080
  286. http://78.24.219.147:8080
  287. http://79.7.158.208
  288. http://79.98.24.39:8080
  289. http://80.249.176.206
  290. http://81.2.235.111:8080
  291. http://82.196.15.205:8080
  292. http://83.169.21.32:7080
  293. http://87.106.136.232:8080
  294. http://87.106.139.101:8080
  295. http://87.106.46.107:8080
  296. http://89.32.150.160:8080
  297. http://91.205.215.66:443
  298. http://91.211.88.52:7080
  299. http://91.236.4.234:443
  300. http://93.156.165.186
  301. http://93.51.50.171:8080
  302. http://94.176.234.118:443
  303. http://95.179.229.244:8080
  304. http://95.213.236.64:8080
Advertisement
Add Comment
Please, Sign In to add comment