Advertisement
ExecuteMalware

2019-06-13 Ursnif/Gozi IOCs

Jun 14th, 2019
2,310
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.82 KB | None | 0 0
  1. SENDERS OBSERVED
  2. kcampbell@flcps.com
  3.  
  4. URSNIF PAYLOAD URLS
  5. http://ckvhss79yo87u.com/p109/mv.php?l=topsv1.dat
  6. http://ckvhss79yo87u.com/p109/mv.php?l=topsv2.dat
  7. http://ckvhss79yo87u.com/p109/mv.php?l=topsv3.dat
  8. http://ckvhss79yo87u.com/p109/mv.php?l=topsv4.dat
  9. http://ckvhss79yo87u.com/p109/mv.php?l=topsv5.dat
  10.  
  11. URSNIF LOADER SERVERS/INFECTION TRAFFIC
  12. http://dnv9619cathy.xyz
  13. https://r96hfhardyee5.com
  14.  
  15. URSNIF PAYLOAD FILE HASH
  16. 0b939bfd5c93cd03b060717d0390179b
  17. 1d00e78029de64570e6684cb18f5e894
  18. 8bfc7ccad057b0b361bca28f173d71fa
  19. 98784bc7e1fddd59f8e0689a4b645cf5
  20. db84d56d987a3abb152f506137641602
  21.  
  22. FOLLOW-UP MALWARE - ICEDID
  23. http://gishti.com/wp-content/uploads/2019/06/asiodn1293.rar
  24.  
  25. ICEDID RAR FILE HASH
  26. 8731ecf64815e8089ce2bc8f7a4a3ec7
  27.  
  28. FOLLOW-UP MALWARE - DRIDEX
  29. 185.175.58.9
  30. 192.48.88.191
  31. 195.123.212.196
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement