Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- emotet banker found on URL AS16276 [51.91.236.193] š«š·
- ā ļøhttps://wwwā§air-pegasusā§com/sips/ADcnKLXD/
- au02458.exe
- windows7_x64
- au02458.exe
- 10
- windows10_x64
- au02458.exe
- 10
- MALWARE CONFIG
- SIGNATURES
- TTP Categories0
- Signatures7
- PROCESSES4
- NETWORK
- TCP
- UDP
- IGMP
- REPLAY MONITOR
- BACKEND
- horse2
- MAX TIME KERNEL
- 144s
- REPORTED
- 2019-12-20T07:22:45Z
- RESOURCE
- win7v191014
- SCORE
- 10
- SUBMITTED
- 2019-12-20T07:20:09Z
- TAGS
- trojan,banker,family:emotet
- TTP
- Target
- au02458.exe
- Filesize
- 717.1kB
- Completed
- 2019-12-20 09:22
- Score
- 10
- /10
- MD5
- 8a40fd86bf18e3cacf8e71891170325a
- SHA1
- 0d1072ec41fbb77ca53ba36624cae6a764808a41
- SHA256
- 1fe9255bab8b718dcbf832be93cc321b8fd0cc432209a233b9cec6134a3869a8
- emotet trojan banker
- Extracted
- Family
- emotet
- rsa_pubkey.plain
- -----BEGIN PUBLIC KEY-----
- MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhAMqZMACZDzcRXuSnj2OI8LeIYKrbUIXL
- faUgIJPwYd305HnaBS2AfA0R+oPxT32r+3BbayI3KguqAn3E+rbwtLhqhOXOlTnY
- 7yvG4ufmwCCkRzc6Sq8baToxmd6y523AIQIDAQAB
- -----END PUBLIC KEY-----
- C2
- 98.178.241.106:80
- 98.178.241.106:80
- 190.171.153.139:80
- 190.171.153.139:80
- 179.5.118.12:8080
- 179.5.118.12:8080
- 45.79.75.232:8080
- 45.79.75.232:8080
- 124.150.175.133:80
- 124.150.175.133:80
- 164.68.115.146:8080
- 164.68.115.146:8080
- 5.189.148.98:8080
- 5.189.148.98:8080
- 46.105.128.215:8080
- 46.105.128.215:8080
- 67.254.196.78:443
- 67.254.196.78:443
- 95.216.207.86:7080
- 95.216.207.86:7080
- 181.46.176.38:80
- 181.46.176.38:80
- 98.15.140.226:80
- 98.15.140.226:80
- 217.12.70.226:80
- 217.12.70.226:80
- 115.179.91.58:80
- 115.179.91.58:80
- 41.190.148.90:80
- 41.190.148.90:80
- 162.144.46.90:8080
- 162.144.46.90:8080
- 211.218.105.101:80
- 211.218.105.101:80
- 212.129.14.27:8080
- 212.129.14.27:8080
- 120.51.83.89:443
- 120.51.83.89:443
- 200.41.121.69:443
- 200.41.121.69:443
- 81.82.247.216:80
- 81.82.247.216:80
- 138.197.140.163:8080
- 138.197.140.163:8080
- 190.5.162.204:80
- 190.5.162.204:80
- 85.109.190.235:443
- 85.109.190.235:443
- 216.75.37.196:8080
- 216.75.37.196:8080
- 41.77.74.214:443
- 41.77.74.214:443
- 86.6.123.109:80
- 86.6.123.109:80
- 203.160.173.202:80
- 203.160.173.202:80
- 211.48.165.9:443
- 211.48.165.9:443
- 158.69.167.246:8080
- 158.69.167.246:8080
- 46.17.6.116:8080
- 46.17.6.116:8080
- 24.27.122.202:80
- 24.27.122.202:80
- 177.103.240.93:80
- 177.103.240.93:80
- 110.142.161.90:80
- 110.142.161.90:80
- 108.184.9.44:80
- 108.184.9.44:80
- 46.105.131.68:8080
- 46.105.131.68:8080
- 211.42.204.154:80
- 211.42.204.154:80
- 37.59.24.25:8080
- 37.59.24.25:8080
- 89.215.225.15:80
- 89.215.225.15:80
- 23.253.207.142:8080
- 23.253.207.142:8080
- 190.38.252.45:443
- 190.38.252.45:443
- 50.116.78.109:8080
- 50.116.78.109:8080
- 94.203.236.122:80
- 94.203.236.122:80
- 86.70.224.211:80
- 86.70.224.211:80
- 174.57.150.13:8080
- 174.57.150.13:8080
- 37.70.131.107:80
- 37.70.131.107:80
- 156.155.163.232:80
- 156.155.163.232:80
- 212.112.113.235:80
- 212.112.113.235:80
- 85.235.219.74:80
- 85.235.219.74:80
- 51.77.113.97:8080
- 51.77.113.97:8080
- 78.46.87.133:8080
- 78.46.87.133:8080
- 200.71.112.158:53
- 200.71.112.158:53
- 201.196.15.79:990
- 201.196.15.79:990
- 190.161.67.63:80
- 190.161.67.63:80
- 112.186.195.176:80
- 112.186.195.176:80
- 82.146.55.23:7080
- 82.146.55.23:7080
- 78.187.204.70:80
- 78.187.204.70:80
- 188.230.134.205:80
- 188.230.134.205:80
- 189.61.200.9:443
- 189.61.200.9:443
- 195.250.143.182:80
- 195.250.143.182:80
- 37.46.129.215:8080
- 37.46.129.215:8080
- 185.244.167.25:443
- 185.244.167.25:443
- 58.93.151.148:80
- 58.93.151.148:80
- 66.229.161.86:443
- 66.229.161.86:443
- 100.38.11.243:80
- 100.38.11.243:80
- 92.16.222.156:80
- 92.16.222.156:80
- 175.127.140.68:80
- 175.127.140.68:80
- 201.183.251.100:80
- 201.183.251.100:80
- 59.158.164.66:443
- 59.158.164.66:443
- 175.103.239.50:80
- 175.103.239.50:80
- 203.153.216.178:7080
- 203.153.216.178:7080
- 154.120.227.190:443
- 154.120.227.190:443
- 124.150.175.129:8080
- 124.150.175.129:8080
- 51.38.134.203:8080
- 51.38.134.203:8080
- 72.27.212.209:8080
- 72.27.212.209:8080
- 210.224.65.117:80
- 210.224.65.117:80
- 128.92.54.20:80
- 128.92.54.20:80
- 91.117.31.181:80
- 91.117.31.181:80
- 69.30.205.162:7080
- 69.30.205.162:7080
- 142.93.87.198:8080
- 142.93.87.198:8080
- 78.186.102.195:80
- 78.186.102.195:80
- 210.171.146.118:80
- 210.171.146.118:80
- 177.144.130.105:443
- 177.144.130.105:443
- 178.134.1.238:80
- 178.134.1.238:80
- 189.225.211.171:443
- 189.225.211.171:443
- 190.93.210.113:80
- 190.93.210.113:80
- 220.78.29.88:80
- 220.78.29.88:80
- 165.100.148.200:8080
- 165.100.148.200:8080
- 72.51.153.27:80
- 72.51.153.27:80
- 95.216.212.157:8080
- 95.216.212.157:8080
- 191.100.24.201:50000
- 191.100.24.201:50000
- 187.250.92.82:80
- 187.250.92.82:80
- 58.185.224.18:80
- 58.185.224.18:80
- 217.181.139.237:443
- 217.181.139.237:443
- 83.156.88.159:80
- 83.156.88.159:80
- 221.154.59.110:80
- 221.154.59.110:80
- 82.79.244.92:80
- 82.79.244.92:80
- 197.94.32.129:8080
- 197.94.32.129:8080
- 181.167.35.84:80
- 181.167.35.84:80
- 42.51.192.231:8080
- 42.51.192.231:8080
- 113.52.135.33:7080
- 113.52.135.33:7080
- 190.17.94.108:443
- 190.17.94.108:443
- 192.210.217.94:8080
- 192.210.217.94:8080
- 190.47.236.83:80
- 190.47.236.83:80
- 176.58.93.123:80
- 176.58.93.123:80
- 95.9.217.200:8080
- 95.9.217.200:8080
- 139.59.12.63:8080
- 139.59.12.63:8080
- 96.234.38.186:8080
- 96.234.38.186:8080
- 82.165.15.188:8080
- 82.165.15.188:8080
- 193.33.38.208:443
- 193.33.38.208:443
- 88.247.26.78:80
- 88.247.26.78:80
- 87.9.181.247:80
- 87.9.181.247:80
- 86.98.157.3:80
- 86.98.157.3:80
- 192.161.190.171:8080
- 192.161.190.171:8080
- 110.2.118.164:80
- 110.2.118.164:80
- 95.255.140.89:443
- 95.255.140.89:443
- 41.111.190.94:80
- 41.111.190.94:80
- 163.172.97.112:8080
- 163.172.97.112:8080
- 186.84.173.136:8080
- 186.84.173.136:8080
- 210.111.160.220:80
- 210.111.160.220:80
- 182.176.116.139:995
- 182.176.116.139:995
- 172.104.70.207:8080
- 172.104.70.207:8080
- 24.28.178.71:80
- 24.28.178.71:80
- 190.101.87.170:80
- 190.101.87.170:80
- 192.241.220.183:8080
- 192.241.220.183:8080
- 91.117.131.122:80
- 91.117.131.122:80
- 69.14.208.221:80
- 69.14.208.221:80
- Emotet
- Drops file in System32 directory
- au02458.exe
- texascors.exe
- Reported IOC
- au02458.exe
- C:\Users\Admin\AppData\Local\Temp\au02458.exe => C:\Windows\SysWOW64\texascors.exe File renamed
- Reported IOC
- texascors.exe
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat File opened for modification
- Suspicious use of SetWindowsHookEx
- au02458.exe
- au02458.exe
- texascors.exe
- texascors.exe
- Suspicious use of WriteProcessMemory
- au02458.exe
- texascors.exe
- Reported IOC
- au02458.exe
- PID 1424 wrote to memory of 1112
- Reported IOC
- texascors.exe
- PID 1992 wrote to memory of 2016
- Suspicious behavior: EmotetMutantsSpam
- au02458.exe
- texascors.exe
- Suspicious behavior: RenamesItself
- au02458.exe
- Suspicious behavior: EnumeratesProcesses
- texascors.exe
- C:\Users\Admin\AppData\Local\Temp\au02458.exe
- "C:\Users\Admin\AppData\Local\Temp\au02458.exe"
- Suspicious use of SetWindowsHookExSuspicious use of WriteProcessMemory
- PID: 1424
- C:\Users\Admin\AppData\Local\Temp\au02458.exe
- --10321ba5
- Suspicious use of SetWindowsHookExSuspicious behavior: EmotetMutantsSpamSuspicious behavior: RenamesItself
- PID: 1112
- C:\Windows\SysWOW64\texascors.exe
- "C:\Windows\SysWOW64\texascors.exe"
- Suspicious use of SetWindowsHookExSuspicious use of WriteProcessMemory
- PID: 1992
- C:\Windows\SysWOW64\texascors.exe
- --f3211a9c
- Suspicious use of SetWindowsHookExSuspicious behavior: EmotetMutantsSpamSuspicious behavior: EnumeratesProcesses
- PID: 2016
- 98.178.241.106:80
- texascors.exe
- 98.178.241.106:80
- texascors.exe
- 190.171.153.139:80
- texascors.exe
- 190.171.153.139:80
- texascors.exe
- 179.5.118.12:8080
- texascors.exe
- 179.5.118.12:8080
- texascors.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement