Advertisement
G0dR4p3

Shade_Ransomware_IOCs_26-04-2019

Apr 26th, 2019
2,004
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.08 KB | None | 0 0
  1. #Shade #Troldesh #Ransomware #Opendir
  2. --------------------------------------------
  3. 26-04-2019 IOC's
  4. --------------------------------------------
  5. Main object- "83250ad954a857da0a6e8470a0543a32fd5811b6887e18012c37935f4e97fe3c.bin.gz"
  6. sha256 0ff291d127d60a7cff6d414820fd0d29e60497d18abb560f25ead25064a0c5d0
  7. sha1 209f2fbb13a2135158be2e5951d3a7ada025f4c8
  8. md5 7acb973ab958197e3075c84748118593
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\1c[1].jpg 7ae7c8f3cd7c94a5ac6f9d1665fd48bfb5762b207624a6f34432e163a658abc9
  11. DNS requests
  12. domain reussitebienetre.numerica-asbl.be
  13. domain whatismyipaddress.com
  14. domain whatsmyip.net
  15. Connections
  16. ip 109.234.165.74
  17. ip 82.197.218.97
  18. ip 86.59.21.38
  19. ip 62.214.6.61
  20. ip 104.16.154.36
  21. ip 154.59.112.69
  22. ip 104.18.34.131
  23. HTTP/HTTPS requests
  24. url http://whatismyipaddress.com/
  25. url http://reussitebienetre.numerica-asbl.be/wp-content/cache/et/8/1c.jpg
  26. url http://whatsmyip.net/
  27.  
  28. OpenDir
  29. http://reussitebienetre.numerica-asbl.be/wp-content/cache/et/8
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement