Advertisement
MalwareMessiagh

Ursnif IOC

Apr 17th, 2019
52,283
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.01 KB | None | 0 0
  1. Dropping URLs:
  2. http://b9nicktof280.com/skoex/po2.php?l=deof[1-12].fgs
  3. http://dwillow100bc.com/skoex/po2.php?l=deof[1-11].fgs
  4. http://ljeffery54ae.top/skoex/po2.php?l=cupk[1-11].fgs
  5. http://s11dorothea4176.com/skoex/po2.php?l=cupk[1-13].fgs
  6. http://151.106.27.208/client[.]rar
  7.  
  8. C2 domains:
  9. ptl8sb.xyz
  10. fooopzrp80yy.info
  11. ksoniay95ee.info
  12. lusgiuea.info
  13. m6692vj7052.com
  14. valphonsosry.info
  15. zindv.club
  16.  
  17. IPs:
  18. 151.106.27.208
  19. 185.139.69.88
  20. 185.204.2.165
  21. 185.204.2.252
  22. 93.170.123.201
  23. 91.240.87.19
  24. 37.230.112.226
  25.  
  26. All of the following subdomains redirect to http://ptl8sb[.]xyz/auth/login :
  27. images.chernogoriatravel.ru
  28. images.bulgariadaily.ru
  29. images.cyprusturizm.ru
  30. images.dominicanabay.ru
  31. images.egyptguides.ru
  32. images.greeceturizm.ru
  33. images.israelvisit.ru
  34. images.maldivesvoyage.ru
  35. images.mavrikiytravel.ru
  36. images.spainbay.ru
  37. images.spainturizm.ru
  38. images.thailandturizm.ru
  39. images.tunisvisit.ru
  40. images.turkeyvisit.ru
  41. images.uaeturizm.ru
  42. images.vietnamvisit.ru
  43. images.italy-info.ru
  44. images.seychelles-voyage.ru
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement