ExecuteMalware

2021-05-17 Unknown Malware IOCs

May 17th, 2021
16,880
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.09 KB | None | 0 0
  1. THREAT IDENTIFICATION: UNKNOWN MALWARE
  2.  
  3. NOTES
  4. Running the executable also drops a .dll and 3 additional (non-executable) files to disk.
  5. Amazingly, the file hash for the .dll appears to have been on VirusTotal since 2009!
  6. There was traffic out to an IP address but all I saw were TCP resets.
  7.  
  8. SUBJECTS OBSERVED
  9. Re: Invoice
  10.  
  11. SENDERS OBSERVED
  12.  
  13. MALDOC FILE HASH
  14. Invoice.iso
  15. b7d01db02b4cc2a8eb206ba19f929d9d
  16.  
  17. UNKNOWN MALWARE FILE HASH
  18. INV.exe
  19. f8273c95045f27e5d6e134b3a549a804
  20.  
  21. Copied and renamed to:
  22. weprasfwjvatm.exe
  23. f8273c95045f27e5d6e134b3a549a804
  24.  
  25. EXTERNAL TRAFFIC
  26. All I saw were TCP reset packets to/from 104.152.188.104
  27.  
  28. ADDITIONAL FILE HASHES
  29. AppData\Local\Temp contains:
  30.  
  31. tambd6oqxct5led0
  32. d3dde1244f9803c4e203358fdb6650e9
  33.  
  34. ynqcndeig
  35. acbd3e7c6c99c4b193f2a1e604bc9976
  36.  
  37. 3bxww6ac1hfs
  38. 96cbec9afc4628836a80fa456b63e5ef
  39.  
  40. Also, in a separate directory under AppData\Local\Temp\:
  41. System.dll
  42. c17103ae9072a06da581dec998343fc1
  43.  
  44. SUPPORTING EVIDENCE
  45. https://www.virustotal.com/gui/file/dc58d8ad81cacb0c1ed72e33bff8f23ea40b5252b5bb55d393a0903e6819ae2f/detection
  46.  
Advertisement
Add Comment
Please, Sign In to add comment