Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: EMOTET
- Dynamic method Used To Get Emotet IOCs:
- 1. Disable Internet connectivity
- 2. Start CMD Watcher
- 3. Open Word documents and grab the base64-encoded Powershell script from CMD Watcher
- 4. CyberChef Recipe to decode:
- From_Base64('A-Za-z0-9+/=',true)
- Decode_text('UTF-16LE (1200)')
- Split('*','\\n')
- Extract_URLs(false)
- 5. Enable internet connectivity and manually download .exe from payload URLs
- 6. Disable internet connection again and run one of the payload executables - capture C2 traffic in Fiddler
- SENDERS OBSERVED
- DOCUMENT FILE HASHES
- 1ff452af811663fe1b2d02d818f213e8
- 20bd788b3f0682c4f0146ae9a554d54b
- 3c9cbc6f2976548609dea56d147b20f1
- 6e17f259490bde55e2e751dd2440d33a
- 73a75e40d5b73fe35ded2a82b1743cbe
- 74c8c361a7a78d096c2dbd629b5abc6d
- 780732f1e23e7e09be35e23412dfeecd
- 7872817339a35c2452babd1f1cc30d5d
- 78fe1505b6851ea884ef555874373ded
- 8edc8e6d88636b9e5350aa2e80f8336d
- 968203d0531ceb11a0e3298c390c2872
- a97740e8d3d27258f8e25de5c1a8e9b4
- b270acc8fd391d79b4d0bfac126cc5ff
- b97a25f68f9c501c487735d5c058757e
- d8641ce9ed475045cf82d82463399ad9
- ec9b276d4666d77203b46d89227fe2cd
- PAYLOAD FILE HASHES
- 13067d944a3c16ce092dbe80d3f69b41
- 30333d086f47122e8bf43b2ff6076bff
- 62f979be778c0d83047350fa2d1de2a1
- 759e289fa582cd91f0e2f69e6baff40a
- 90c500199a04f70cd810e55c56e01cea
- d2916d363b9d9b7f16e8210da16f42bf
- ecfc2d4481aaa0dfc8aaaa1fad367f56
- MALDOC DOWNLOAD URLs
- http://aarunya.in/wp-admin/swift/3jc4jqgai3rf/98382623658csjsmcfrnnlx032w6e9/
- http://af2play.online/cadic/DOC/q9n256866279950911462178txj81v0getc0nq8d84nl/
- http://agoty.org/wp-content/uploads/1569700949_aQmJGB6jChk2g_6711054_esaD78/e0n1mn2x_6ygf_41wR_vLbhodeZ/05uoy_108vytsx7/
- http://akzy.top/h8ioc8/Documentation/
- http://bushireinlondon.co.uk/fonts/available_disk/test_forum/676747_SYh9NiV2/
- http://careco.parts/wp-content/Uf/
- http://cellstore.net.br/wp-admin/protected-zone/interior-zgirj9bvpgy5ef1-0z7d5cqgj949/KL4SoBjA0s-nGbvgduN/
- http://cepabol.noticias.bo/alfacgiapi/ybaurum4dq/
- http://cleardristi.com/cleardristi.com_WP_INSTALL/g84oq8lq9ek_d0qdnl3l0gkrr_module/corporate_wkg55rof6x_cf5kxjphwqyz/who5_06y576/
- http://demo.xoweb.cn/static/public/yn4g1lj32bix/
- http://drive.medisail.fr/lib/INC/
- http://dsoft.software/euy/lj/
- http://elilaifs.cn/wp-admin/parts_service/jecxwnaz1j/
- http://essah.in/new/jke8sdg-a892-41684/
- http://exchangecamp.ir/wp-admin/Documentation/
- http://guoxiaorui.cn/wp-admin/private_FbVo_PSouiS1uKbbyfs/interior_forum/9005074_1StXFeoXH8jW9/
- http://hirebyprofession.com/assets/lm/
- http://linhkien36.cf/wp-admin/personal_array/open_forum/248250499770_SkHduGJkxpK/
- http://linhkien36.net.co/wp-admin/browse/
- http://longphuong.tk/wp-admin/browse/buz7el/
- http://minibus-hire-basingstoke.co.uk/js/erhXjTo/
- http://money-crdt.ru/q0by2r/invoice/
- http://movie.cxyw.net/fork/LLC/jj0av1ems/xrgxn858627574n193e6s4zoqd2/
- http://pasca.fapet.ub.ac.id/l/sites/
- http://psotm.pl/wp-includes/closed_zone/interior_area/963338392_kCrsPUBs/
- http://ranks.hoonicorns.pt/comp3/Overview/00giwvmzhy/s04054954269w9vtvn5tqlan/
- http://sample.tri-comma.com/wp-admin/FILE/
- http://stayfitphysio.ca/wp-content/plugins/balance/fzozekbnnb/
- http://steelworks-students.com/wp-admin/FILE/ype8vbeho2jn/
- http://sul.t.12cotacao.us/clicar/32551467/
- http://swingcommerce.com/wp-content/uploads/closed_box/YHim0z_mvqyzrJPRQe_76jy_mxy1me3/pa84uf2f2oqj_sv590sx04s45wy/
- http://tangramadigital.tecnologia.bo/wp-admin/87296192280_GCdHQit_473088_QQLl2FZUTJVfNgF/guarded_forum/hfwF5TB7kQ_uLMfnpJjwN63/
- http://tarisfotografi.com/aup/Overview/
- http://temp.tara.edu.lk/wp-content/uploads/2020/personal-DVdtZjL-mQSSVjj/test-profile/17169653973-18JoYS1FAiHzZCDR/
- http://teste.hoonicorns.pt/ddfcn41dj/payment/epwsnm/
- http://tophoras.hoonicorns.pt/comp3/z9-9elt-66213/
- http://triptovacations.com/wp-content/wadJUaE/
- http://ulfhorror.com/wp-admin/83279465106718/7fkhh84265327972167057acuknjrmhrfbxz9bdd/
- http://united-vision.net/smart-school-5.0/available_disk/open_space/4648749024_erM9SWF/
- http://watkins.mitchellpwright.com/wp-includes/docs/lg2wm6zn/sxhgff291213969722cb2tpmjwffm/
- http://web86.s146.goserver.host/hk9jj/CchogvhEi/
- http://wmzart.com/wp-includes/available-box/special-area/682477561403-C9hB9Em/
- http://www.0931tangfc.com/images/multifunctional_d1hiw_ewtuc2kwj/verifiable_space/2w3z_403y7v5934/
- http://www.ajanews.asia/wp/Document/5r65712504026116389jmyzp09zw2b3sfn63/
- http://www.aumhealings.org/wp-admin/docs/1izhzmhbo/
- http://www.carloni.com.br/wp-includes/closed-module/corporate-090menkn8gyh0v-flesu2z9rvhj/xzus-294v8y/
- http://www.dawoodsupermarket.com/wp-admin/eNUOCqw/
- http://www.gdstechnologies.co.in/app/eTrac/
- http://www.leonardoenergie.it/media/balance/
- http://www.mikesar.com/cgi-bin/FILE/9iy3rbp/yc697386432801482480z1o1srx37/
- http://www.mikesar.com/cgi-bin/rqag0gz/
- http://www.oakeno.com/wp-admin/801579841823_XUeIoA6k4S663_zone/test_area/rgfnwniaa_3x7u49063/
- http://www.quintapavicich.com.ar/3e8mgy/private-module/individual-profile/wo718fkda46wwqw-04xs44/
- http://www.timelyrain.top/wp-includes/ID3/parts_service/enlbnfk4xl/
- http://wx.yuan.fit/data/multifunctional-ni7pt4lu-igevj/interior-profile/6kj-s2ss899y0wtzy/
- http://yihe.fcglobal.com.cn/phpsso_server/ej9ni-qb-014/
- http://ypbb.or.id/wp-content/bao-5yp-968/
- http://yuan.fit/wp-admin/v3na-c7uu-042786/
- http://zeing-kor.com/b/common_array/open_12aprkbzsnv01y_4uawa/87933126050098_FOkxEXj/
- http://zingadata.com/wp-content/protected-680154094967-NkP2aIaG/guarded-TDUl5Ai-CW9oksOL8Jh/1705605-2vBjnW/
- https://1haowan.cn/wp-includes/protected-disk/open-653784029-jIpt1NW/mzWXqM-lk28z57HqL/
- https://affutes.netavantage.com/wp-content/closed-9858205266-15AeMiAnE9/open-warehouse/9YpjLKfyXx-lzyNfHLNn/
- https://ahdaaf.me/site/attachments/8uawrs20822876186p63anwn63gv9dv/
- https://allamanolibrary.com/zyro/public/
- https://anikwp.com/6d3jv/personal_box/open_Loa8_MvQFjwwmkY/8064625563_dYBaZNqg0f2/
- https://antalyalogodestek.com/wp-content/public/
- https://bawaslu.wonosobokab.go.id/wp-content/iskGT/
- https://construtoraaguiar.com.br/wp-includes/available-ph1S-smmNI7wAUDV42iB/special-portal/528912442-bGAY3pyBEmP/
- https://daniwilkinson.co.uk/dup-installer/sites/3u01718046821pkh6l38v42wa3e1eiw/
- https://delhisuppliers.in/wp-admin/closed_array/open_space/gwr2soq_4wy25t3026/
- https://dinghaomcc.com/wp-admin/protected-resource/interior-area/lnlnimb-yw16sztu69/
- https://doraflob.com/fef2/Document/
- https://fitmode.vn/wp-admin/common-09174168043-bWUexpZAf3/guarded-space/xvy4fksg-66xy89524359w/
- https://grafikos.com.ar/cgi-bin/open-43667-nqZwUKt5/security-3lrg-AjxU8K4c/12097743559-MsAVhVJHCjVT4bV/
- https://hightea.tk/wp-admin/LLC/uxblj70750248131jyb5yjz51vq9r3zg0yo/
- https://ideanetsolutions.com/wp-admin/multifunctional-zone/guarded-mglbz8f9qqm-77foumy8y423bo/ZqnWyCb1ePV-yhG1xbpjL/
- https://ineedmoney.loan/wp-content/dAXpzb/
- https://koncenful.com/wp-content/lm/hmhj52/ook7ri689941810111164mlk5ffuksnm6anf/
- https://konipapua.com/wp-content/uploads/
- https://konipapua.com/wp-content/uploads/zpqn7d-w8-418/
- https://max-hoffmann-webdesign.de/eTrac/
- https://momentomt.com.br/wp-includes/5lto7-by5y-45/
- https://qhn.vn/default/attachments/
- https://qrtalk.nl/wp-content/docs/f6k3vrc0/
- https://robotena.org/wp-admin/dhly-qh6p-87788/
- https://steer2vision.com/recurringo/Overview/t8oku994412361893ciornz3iuaysczvm/
- https://www.chinavok.com/wv7kv/multifunctional-gmgtAcb-XzR6tiFghuo/additional-gN3u1-JPwnriOV0YM/wg7hzo1jit-0sus2x/
- https://www.fleuve.tk/wp-admin/statement/zfkdtqgff/
- https://www.pharma-israel.org.il/wp-content/DOC/
- https://www.strain.ee/site/82kxurzh-4x7-27/
- https://www.supercutscissors.com/wp-content/uploads/11a-t48x-5941/
- https://www.ziyuan.tech/wp-admin/Documentation/
- EMOTET PAYLOAD URLs
- http://abatiy.com/yaa/po0395/
- http://cpads.net/7iuhq/mri/
- http://crm.shaayanpharma.com/application/ffltO/
- http://fivestarcleanerstx.com/wp-content/mu-plugins/2CLid868/
- http://shubhinfoways.com/p/XEcc5x1qx73/
- http://sustainableandorganicgarments.com/komentarz/KHF6ry92657/
- http://test2.cxyw.net/hyeht3/aWybkzi/
- http://topgameus.com/AutoIT_UngdungOnline/zqjqel/
- http://www.szhealthshield.com/websiteguide/k82i/
- http://zazabajouk.com/cf9r4nd/Xsma350581/
- https://aliyousefpoor.com/wp-admin/Gkt8B41139/
- https://bhandaraexpress.com/wp-includes/0Iw2jW2/
- https://digitalcon7.net/wp-snapshots/0Wn/
- https://e2e-solution.com/sandbox/Sv2880/
- https://exam.ylsbmeirong.com/data/tjEyH973/
- https://fivestarcleanerstx.com/wp-content/mu-plugins/2CLid868/
- https://ramukakaonline.com/wp-includes/cxSzmSXN/
- https://skenglish.com/wp-admin/o0gf/
- https://ssuse.com/wp-content/uploads/IMv2xyEc3/
- https://thesuperservice.com/wp-admin/rL00/
- https://tyres2c.com/wp-admin/zu2h/
- https://www.elseelektrikci.com/wp-content/hedk3/
- https://www.packersmoversmohali.com/wp-includes/pgmt4x/
- https://www.rviradeals.com/wp-includes/LeDR/
- https://www.tri-comma.com/wp-admin/MmD/
- EMOTET C2s
- http://101.187.97.173
- http://103.86.49.11:8080
- http://104.131.103.37:8080
- http://104.131.11.150:443
- http://104.131.41.185:8080
- http://104.131.44.150:8080
- http://104.236.161.64:8080
- http://104.236.246.93:8080
- http://104.247.221.104:443
- http://108.48.41.69
- http://109.117.53.230:443
- http://109.74.5.95:8080
- http://110.143.151.194
- http://110.145.77.103
- http://111.67.12.221:8080
- http://113.160.130.116:8443
- http://113.190.254.245
- http://114.109.179.60
- http://116.203.32.252:8080
- http://12.162.84.2:8080
- http://121.124.124.40:7080
- http://137.59.187.107:8080
- http://137.74.106.111:7080
- http://139.130.242.43
- http://139.59.60.244:8080
- http://143.0.87.101
- http://149.62.173.247:8080
- http://153.126.210.205:7080
- http://157.245.99.39:8080
- http://162.154.38.103
- http://162.241.92.219:8080
- http://168.235.67.138:7080
- http://169.239.182.217:8080
- http://170.81.48.2
- http://172.104.169.32:8080
- http://173.91.22.41
- http://176.111.60.55:8080
- http://177.139.131.143:443
- http://177.144.135.2
- http://177.66.190.130
- http://177.72.13.80
- http://178.79.163.131:8080
- http://181.120.79.227
- http://181.129.96.162:8080
- http://181.31.211.181
- http://185.94.252.104:443
- http://185.94.252.12
- http://185.94.252.13:443
- http://185.94.252.27:443
- http://186.208.123.210:443
- http://186.250.52.226:8080
- http://186.70.127.199:8090
- http://187.162.248.237
- http://187.51.47.26
- http://189.218.165.63
- http://190.108.228.62:443
- http://190.144.18.198
- http://190.147.137.153:443
- http://190.160.53.126
- http://190.163.1.31:8080
- http://190.17.195.202
- http://190.181.235.46
- http://190.194.242.254:443
- http://190.229.148.144
- http://190.55.181.54:443
- http://190.6.193.152:8080
- http://192.241.143.52:8080
- http://192.241.146.84:8080
- http://2.47.112.152
- http://200.41.121.90
- http://200.55.243.138:8080
- http://201.173.217.124:443
- http://201.213.32.59
- http://202.62.39.111
- http://203.153.216.189:7080
- http://203.25.159.3:8080
- http://204.225.249.100:7080
- http://207.255.37.143
- http://209.141.54.221:8080
- http://210.165.156.91
- http://212.51.142.238:8080
- http://212.71.237.140:8080
- http://217.13.106.14:8080
- http://217.199.160.224:7080
- http://219.92.13.25
- http://222.214.218.37:4143
- http://24.1.189.87:8080
- http://31.31.77.83:443
- http://37.139.21.175:8080
- http://37.187.72.193:8080
- http://41.60.200.34
- http://45.161.242.102
- http://46.105.131.79:8080
- http://46.105.131.87
- http://46.214.11.172
- http://46.28.111.142:7080
- http://5.196.35.138:7080
- http://5.196.74.210:8080
- http://5.39.91.110:7080
- http://50.116.86.205:8080
- http://50.28.51.143:8080
- http://51.255.165.160:8080
- http://58.153.68.176
- http://60.130.173.117
- http://61.19.246.238:443
- http://61.92.159.208:8080
- http://62.138.26.28:8080
- http://62.75.141.82
- http://68.183.170.114:8080
- http://68.183.190.199:8080
- http://70.32.115.157:8080
- http://70.32.84.74:8080
- http://72.47.248.48:7080
- http://73.11.153.178:8080
- http://74.208.45.104:8080
- http://75.139.38.211
- http://77.55.211.77:8080
- http://77.90.136.129:8080
- http://78.189.165.52:8080
- http://78.24.219.147:8080
- http://79.7.158.208
- http://79.98.24.39:8080
- http://80.249.176.206
- http://81.2.235.111:8080
- http://82.196.15.205:8080
- http://83.169.21.32:7080
- http://87.106.136.232:8080
- http://87.106.139.101:8080
- http://87.106.46.107:8080
- http://89.32.150.160:8080
- http://91.205.215.66:443
- http://91.211.88.52:7080
- http://91.236.4.234:443
- http://93.156.165.186
- http://93.51.50.171:8080
- http://94.176.234.118:443
- http://95.179.229.244:8080
- http://95.213.236.64:8080
Advertisement
Add Comment
Please, Sign In to add comment