Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #fareit #pony #RTF11882
- https://pastebin.com/wyRGBXfj
- previous contact:
- https://pastebin.com/u0D14L5r
- FAQ:
- https://radetskiy.wordpress.com/?s=fareit
- attack_vector
- --------------
- email attach .doc (RTF) > 11882 > GET URL > \appdata\roaming\*.exe
- email_headers
- --------------
- n/a
- files
- --------------
- SHA-256 742e8b89226e7ab2dbaa2bdf998a80ec84c5b989a82512dcd8c9ae83915edae0
- File name PO-4300023687.doc [Rich Text Format data, version 1]
- Last analysis 2019-02-27 10:25:11 UTC
- SHA-256 8ae23c556d2dc1fb114eb4d9128766ee9765884e2748c32e5e643fc23be7fc7c
- File name we.exe [PE32 executable (GUI) Intel 80386, for MS Windows]
- File size 679.5 KB
- activity
- **************
- PL_SRC
- enderezadoypinturaag{.} com/vfls/we.exe
- C2
- iat-dz{.} com/papi/gate.php
- iat-dz{.} com/papi/shit.php
- netwrk
- --------------
- 192.185.28.238 www.enderezadoypinturaag{.} com GET /vfls/we.exe HTTP/1.1 no User Agent
- 145.239.232.110 www.iat-dz{.} com POST /papi/gate.php HTTP/1.0 Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
- 145.239.232.110 www.iat-dz{.} com GET /papi/shit.php HTTP/1.0 Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
- comp
- --------------
- EQNEDT32.EXE 968 TCP localhost 49237 192.185.28.238 80 ESTABLISHED
- fdgdfsdafgdfsd.exe 2976 TCP localhost 49238 145.239.232.110 80 ESTABLISHED
- proc
- --------------
- "C:\Program Files (x86)\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
- C:\Users\operator\AppData\Roaming\fdgdfsdafgdfsd.exe
- cmd /c ""C:\tmp\1663343.bat" "C:\Users\operator\AppData\Roaming\fdgdfsdafgdfsd.exe" "
- persist
- --------------
- n/a
- drop
- --------------
- C:\Users\operator\AppData\Roaming\fdgdfsdafgdfsd.exe * (remove itself!!)
- # # #
- https://www.virustotal.com/#/file/742e8b89226e7ab2dbaa2bdf998a80ec84c5b989a82512dcd8c9ae83915edae0/details
- https://www.virustotal.com/#/file/8ae23c556d2dc1fb114eb4d9128766ee9765884e2748c32e5e643fc23be7fc7c/details
- https://analyze.intezer.com/#/analyses/87499ebd-0f95-4e87-8d59-03a11d4ae8e9
- VR
- @
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement