I don't have the raw decode since i've not decoded it.
edit: i asked a little birdy, it's attached.
I've found these domains in relation:
raphclickable.com/foh/file.php
onepagegrinsd.com/foh/file.php
unstandardclo.net/foh/file.php
measuredtrick.com/foh/file.php
opportunitiess.su/foh/file.php
upanddownrein.com/foh/file.php
Possibly also in relation:
omituniversit.com/adu/file.php
zopapublishedn.su/adu/file.php
eagencygraphp.net/adu/file.php
demandmeticul.net/adu/file.php
dollarsremons.com/adu/file.php
onestopinstru.net/adu/file.php
--
http://www.spamhaus.org/sbl/query/SBL193024
ewsoulelysejh.com/wel/file.php
And malwr seem to know a dropper: https://malwr.com/analysis/OTNkZTMyMTVm ... MxYzM0YWI/
behavioral analysis is interesting: 86734234434.exe -> fnmod_32.exe i've already see this user_execute on ZeusVM (36CE0A33.zip unpacked payload)
S21 guys observed an involution of the 3.1.0.0, maybe because actors switched on ZeusVM :?:
one ZeusVM use the same ASN of a Citadel 3.1.0.0: http://www.urlquery.net/report.php?id=7654694 and guess what, it's the one who download fnmod_32.exe
Some others 3.1.0.0 in attachement.
https://www.virustotal.com/en/file/3202 ... 394564044/
https://www.virustotal.com/en/file/b71b ... 394564049/
https://www.virustotal.com/en/file/f45b ... 394564053/
edit: i asked a little birdy, it's attached.
I've found these domains in relation:
raphclickable.com/foh/file.php
onepagegrinsd.com/foh/file.php
unstandardclo.net/foh/file.php
measuredtrick.com/foh/file.php
opportunitiess.su/foh/file.php
upanddownrein.com/foh/file.php
Possibly also in relation:
omituniversit.com/adu/file.php
zopapublishedn.su/adu/file.php
eagencygraphp.net/adu/file.php
demandmeticul.net/adu/file.php
dollarsremons.com/adu/file.php
onestopinstru.net/adu/file.php
--
http://www.spamhaus.org/sbl/query/SBL193024
ewsoulelysejh.com/wel/file.php
And malwr seem to know a dropper: https://malwr.com/analysis/OTNkZTMyMTVm ... MxYzM0YWI/
behavioral analysis is interesting: 86734234434.exe -> fnmod_32.exe i've already see this user_execute on ZeusVM (36CE0A33.zip unpacked payload)
S21 guys observed an involution of the 3.1.0.0, maybe because actors switched on ZeusVM :?:
one ZeusVM use the same ASN of a Citadel 3.1.0.0: http://www.urlquery.net/report.php?id=7654694 and guess what, it's the one who download fnmod_32.exe
Some others 3.1.0.0 in attachement.
https://www.virustotal.com/en/file/3202 ... 394564044/
https://www.virustotal.com/en/file/b71b ... 394564049/
https://www.virustotal.com/en/file/f45b ... 394564053/
Attachments
infected
(60.43 KiB) Downloaded 87 times
(60.43 KiB) Downloaded 87 times
infected
(846.59 KiB) Downloaded 123 times
(846.59 KiB) Downloaded 123 times