Skip to content

Commit

Permalink
Adding IoC data for Metamorfo
Browse files Browse the repository at this point in the history
  • Loading branch information
bogdanbotezatu committed Jun 4, 2020
1 parent b26bfb1 commit 134ee2f
Show file tree
Hide file tree
Showing 3 changed files with 4,984 additions and 0 deletions.
356 changes: 356 additions & 0 deletions metamorfo_malware/decrypted_strings.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,356 @@
#sTrCmdOK#
#S#
#hKey#
<#>
#sTrSktPrin#
#ON-LINE#
#strPingOk#
#Handle#
#xyScree#
#strResolucao#
#Convite#
#ConvitRC#
-Bad-
#Iniciar#
#strIniScree#
#beginning#
sValueT<#>
gets:
siZeOk:
hxxps://docs.google.com/document/d/1JJDguAOxbrMmzTjTPAxBcbdfJacrwCzQJsogXiWwRVc/edit?usp=sharing
WinHttp.WinHttpRequest.5.1
GET
&quot;
inicio
fim
host
open
MagnifierHost
Host Window
MagnifierWindow
SeShutdownPrivilege
TEMP
\ConfXTheme
Gerenciador de Tarefas do Windows
Gerenciador de Tarefas
DWMAPI.dll
DwmEnableComposition
Cursor_1
Tela:Bloqueada
IMG:01
Win:
IMG:02
internet explorer
- internet explorer
-#-
-#-internet explorer
google chrome
- google chrome
-#-google chrome
mozilla firefox
- mozilla firefox
-#-mozilla firefox
SunAwtFrame
C:\Sicoobnet
BL-0.ini
ddmmyyyy
.ini
Aplicativo sicoob
sicoob
AplicativoBradesco.exe
Aplicativo bradesco
Banco Bradesco
NavegadorExclusivoBradesco.exe
Erro: Caminho Inválido!
.exe
331030E86997B567EC1BDA0378819D478E5BF736270D5B9C4EEC172BD90A729F48E1
.lnk
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
core.exe
C0R3
RapportService.exe
R4pp0rt
63E71AD277A652C46A9455
LO_01
LO_02
LO_04
LO_05
LO_07
LO_08
LO_03
LO_06
LO_09
LO_11
LO_10
LO_12
[bb.com.br]
Banco do Brasil
Banco Bradesco | Pessoa Física, Exclusive, Prime e Private
Bradesco
Pessoa jurídica | Bradesco
Bradesco JuJu
Banco Itaú
Banco Itáu
Santander
Banco Santander
sicredi
Banco Sicredi
Mercantil
internetbanking
Caixa Economica
Banco Sicoob
Unicred Portal
Unicred
Internet Banking BNB
Banco BNB
Banco Inter
Banco Intermedium
Banco MUFG Brasil S.A.
Banestes - Internet Banking
Banestes
Internet Banking
Bancos Geral
Banco do Estado do Pará S/A
Cetelem | Login
Cetelem
Cooperativa de Crédito
Nova Home | Internet
Banco Safra
SafraNet
BANCO PAULISTA
UniprimeCentral
Uniprime
Bem vindo ao seu BMG
BMG
Portal - Banco Votorantim
Votorantim
Pine Online
NBC BANK
Tribanco Online
Tribanco
Banco Alfa
Banco Indusval & Partners
Banco Indusval
Portal Internet Banrisul
Banrisul
Banco Original
Acesse sua conta Celcoin
Celcoin
Login - Nubank
Nubank
BRB Banknet
Banco de Brasília
Banco da Amazônia
Banese
BancoTopazioInternetBanking
Banco Topazio
BancoIndustrial
Banco Industrial
Daycoval
bradesco
CIDETRAN
Viacredi
PagueVeloz Serviços de Pagamentos
Pague Veloz
Banco Safra - Internet Banking Pessoa Jurídica
Pessoa Jurídica | Internet
Safra Jurídica
Pessoa Física | Internet
Safra Física
Bradesco Exclusive
Bradesco Prime
Prime
Banco Bradesco S/A
Bradesco Private Bank
Bradesco Private
CB58909BD0B16B89E87DE07AB778A98CC447A5874F94E9010F3DDC45FF54D10EC076899C5C83ACBCA43A29B452CA668E51CD598F83BCCB7F868A8EA7ADB85E9C90
*.*
Aplicativo Itau
Microsoft\Windows\Themes
#RE#
\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
ProductName
-
HSA5JIDUGPLPUIP4X7SNT2XLX
8581A557F62C
TTL_03
TTL_PISCA
TTL_02
TTL_01
#mde#
#mdd#
#mmv#
#mue#
#mud#
#kd#
#ku#
#clb#
133FF21764
#Cmd#
#RC#
#QR#
#QRCODE#
RC01
TNTBBRCQR
RC02
RC03
RC04
RC05
TNTSARCQR
RC06
RC07
RC08
RC09
RC10
RC11
RC12
qlmacxenze=
pkpnpmcgul=
ryakpxscha=
obmiunnict=
TEST
muilfoeqbw=
btyjuhvxhl=
$_POST
text/html, */*
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
application/x-www-form-urlencoded
Once
2g.vc
hxxp://buleva[.]webcindario[.]com/my/
\2g.vc
Scripting.Encoder
JLI_CmdToArgs
Wscript.Shell
Wscript.Network
startup
*.vbs
*.cmd
*.lnk
on error resume next
Set objShell = CreateObject("WScript.Shell")
set fsysobj = createobject("scripting.filesystemobject")
runcmd = "cmd /k c: & cd\ & cd
&
if fsysobj.fileexists (
) then
objShell.run(runcmd),0
End If
<NAMEFILE>
objShell
fsysobj
runcmd
.vbs
C:\Users\Public\Downloads\
\fim
L01
L02
L03
L04
L05
L06
L07
L08
L09
L10
L11
L12
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVW XYZ
MAINICON
Static
msctls_progress32
P01
I01B
I01QR
I01OK
E01
P02
I02
I02OK
E02
P03
I03B
I03OK
E03
P04
I04B
I04OK
E04
TTL_QR
TTL_04
TNTB01
TNTB02
TNTB03
TNTB04
pnl1
img1backChrome_WidgetWin_1
OK
imgqr
edt1campo
pnl2
img2backgroud
OK2
edt2campo
pnl3
img3backChrome_WidgetWin_1
OK3
cordenada
Arial
edt3campo
pnl4
img4backChrome_WidgetWin_1
OK4
edt4campo
pnl5
img5backChrome_WidgetWin_1
OK5
edt5campo
PNL_PISCA
backpiscaChrome_WidgetWin_1
OKPISCA
piscacampo
TTL_05
TNTD01
TNTD02
TNTD03
TNTD04
TNTD05
TNTDPISCA
clean
T0
T7
T4
T6
T3
T5
T8
T1
T9
T2
TNTC01
lbl1
Tahoma
lbl2
dd
!99/99/0000;1;_
/ /
TNTI01
TNTI02
TNTI03
TNTI04
img1clean
img2clean
img3clean
campo
img4clean
img5clean
QR
pnlRec
TNTSQR
TNTS01
TNTS02
TNTS03
TNTS04
TNTSIC01
TNTSIC02
TNTCOOB01
Loading

0 comments on commit 134ee2f

Please sign in to comment.