Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #GandCrab v.4 #Trojan #Ransomware
- -----------------------------------
- 27-08-2018 IOC's
- -----------------------------------
- Main object- "__ppt__.js"
- sha256 747cd2a35232496048348848be88146396f89319a22864da179ad88f83b98385
- sha1 f5af96f0200a249418f7eb19457bc1cece2577a7
- md5 da2c219b0684d15637346a0f42adc98b
- Dropped executable file
- sha256 C:\Users\admin\pjgvqoemd.exe 5930513fa35d1ac38d92cbd4b5be982bbdbeb5b4e2c5274a8bf33ce0bdef933c
- DNS requests
- domain www.billerimpex.com
- domain www.macartegrise.eu
- domain www.poketeg.com
- domain perovaphoto.ru
- domain asl-company.ru
- domain www.fabbfoundation.gm
- domain www.wash-wear.com
- domain www.perfectfunnelblueprint.com
- domain boatshowradio.com
- domain cevent.net
- domain bellytobabyphotographyseattle.com
- domain pp-panda74.ru
- domain alem.be
- domain dna-cp.com
- domain www.mimid.cz
- domain 6chen.cn
- domain wpakademi.com
- domain goodapd.website
- domain www.cakav.hu
- domain oceanlinen.com
- domain acbt.fr
- domain nesten.dk
- domain koloritplus.ru
- domain h5s.vn
- domain topstockexpert.su
- domain tommarmores.com.br
- domain zaeba.co.uk
- domain www.n2plus.co.th
- domain www.ismcrossconnect.com
- domain www.toflyaviacao.com.br
- domain big-game-fishing-croatia.hr
- domain mauricionacif.com
- domain www.lagouttedelixir.com
- domain www.rment.in
- domain aurumwedding.ru
- domain www.krishnagrp.com
- domain bloghalm.eu
- domain cyclevegas.com
- domain test.theveeview.com
- domain www.relectrica.com.mx
- domain relectrica.com.mx
- domain bethel.com.ve
- domain vjccons.com.vn
- domain marketisleri.com
- domain hoteltravel2018.com
- domain royal.by
- domain smbardoli.org
- domain blokefeed.club
- domain www.himmerlandgolf.dk
- domain krasnaypolyana123.ru
- domain unnatimotors.in
- domain picusglancus.pl
- Connections
- ip 103.107.17.102
- ip 104.27.184.39
- ip 104.27.187.113
- ip 103.27.238.31
- ip 104.24.105.13
- ip 104.24.102.153
- ip 104.27.163.241
- ip 104.28.31.160
- ip 107.178.113.162
- ip 104.31.76.95
- ip 146.66.72.87
- ip 144.217.47.134
- ip 137.74.238.33
- ip 179.188.11.34
- ip 149.56.154.141
- ip 178.238.37.164
- ip 178.33.233.202
- ip 171.244.34.167
- ip 185.135.88.105
- ip 173.247.242.133
- ip 188.64.184.90
- ip 188.165.53.185
- ip 217.174.149.130
- ip 213.186.33.186
- ip 223.26.62.72
- ip 202.43.45.181
- ip 217.160.0.234
- ip 191.252.51.37
- ip 192.35.177.64
- ip 213.186.33.3
- ip 51.68.50.168
- ip 69.73.180.151
- ip 37.140.192.32
- ip 67.227.236.96
- ip 31.41.45.138
- ip 50.87.58.165
- ip 52.29.192.136
- ip 66.96.147.67
- ip 70.40.197.96
- ip 94.231.109.239
- ip 95.213.173.173
- ip 87.236.16.29
- ip 87.236.16.208
- ip 80.77.123.23
- ip 87.236.19.51
- ip 87.236.16.31
- ip 93.125.99.121
- ip 89.252.187.72
- ip 77.104.144.25
- HTTP/HTTPS requests
- url http://blokefeed.club/
- url http://blokefeed.club/data/imgs/seesheesso.jpg
- url http://www.macartegrise.eu/wp-content/image/sedese.gif
- url http://www.billerimpex.com/
- url http://www.macartegrise.eu/
- url http://www.poketeg.com/
- url http://www.poketeg.com/content/pictures/moamim.png
- url http://asl-company.ru/wp-content/imgs/imde.gif
- url http://perovaphoto.ru/wp-content/image/daes.bmp
- url http://pp-panda74.ru/static/pics/semo.gif
- url http://pp-panda74.ru/
- url http://www.wash-wear.com/
- url http://www.wash-wear.com/includes/image/kehe.png
- url http://www.fabbfoundation.gm/data/graphic/fufu.gif
- url http://www.fabbfoundation.gm/
- url http://perovaphoto.ru/
- url http://www.perfectfunnelblueprint.com/data/images/mesekehekade.bmp
- url http://www.perfectfunnelblueprint.com/
- url http://asl-company.ru/
- url http://alem.be/data/pics/deam.jpg
- url http://alem.be/
- url http://dna-cp.com/
- url http://boatshowradio.com/content/graphic/imimseruda.gif
- url http://boatshowradio.com/
- url http://cevent.net/
- url http://cevent.net/wp-content/graphic/dafuruso.png
- url http://acbt.fr/content/image/esruimhe.jpg
- url http://www.mimid.cz/
- url http://www.mimid.cz/includes/imgs/zukeseamde.jpg
- url http://www.cakav.hu/content/pictures/hethsomo.jpg
- url http://wpakademi.com/
- url http://www.cakav.hu/
- url http://acbt.fr/
- url http://wpakademi.com/data/tmp/thkadedede.png
- url http://nesten.dk/
- url http://6chen.cn/
- url http://tommarmores.com.br/includes/imgs/dekaes.bmp
- url http://tommarmores.com.br/
- url http://6chen.cn/static/pics/dedadehefu.bmp
- url http://oceanlinen.com/
- url http://oceanlinen.com/news/pictures/thimketh.gif
- url http://topstockexpert.su/
- url http://koloritplus.ru/content/imgs/keru.bmp
- url http://marketisleri.com/
- url http://h5s.vn/uploads/pictures/somo.jpg
- url http://nesten.dk/news/pics/mozu.gif
- url http://h5s.vn/
- url http://koloritplus.ru/
- url http://www.n2plus.co.th/static/graphic/rumesofu.jpg
- url http://www.n2plus.co.th/
- url http://big-game-fishing-croatia.hr/
- url http://www.krishnagrp.com/
- url http://www.lagouttedelixir.com/includes/imgs/medame.bmp
- url http://www.toflyaviacao.com.br/data/pics/meimamme.gif
- url http://mauricionacif.com/
- url http://www.rment.in/
- url http://www.toflyaviacao.com.br/
- url http://www.lagouttedelixir.com/
- url http://www.rment.in/data/pictures/somemoames.gif
- url http://aurumwedding.ru/
- url http://www.ismcrossconnect.com/
- url http://test.theveeview.com/
- url http://bethel.com.ve/
- url http://test.theveeview.com/wp-content/images/fuim.gif
- url http://www.ismcrossconnect.com/static/graphic/fururuth.bmp
- url http://aurumwedding.ru/includes/tmp/immothme.bmp
- url http://relectrica.com.mx/
- url http://mauricionacif.com/content/assets/damodafu.png
- url http://vjccons.com.vn/
- url http://www.himmerlandgolf.dk/
- url http://royal.by/
- url http://cyclevegas.com/
- url http://bloghalm.eu/wp-content/images/zuimthzu.png
- url http://bloghalm.eu/
- url http://vjccons.com.vn/data/assets/zusofuke.bmp
- url http://smbardoli.org/
- url http://unnatimotors.in/
- url http://smbardoli.org/content/imgs/imesda.jpg
- url http://krasnaypolyana123.ru/wp-content/image/zukehe.png
- url http://hoteltravel2018.com/
- url http://krasnaypolyana123.ru/
- url http://picusglancus.pl/static/tmp/mefuesdaru.bmp
- url http://picusglancus.pl/
- url http://hoteltravel2018.com/content/images/imkeda.bmp
- url http://www.himmerlandgolf.dk/uploads/assets/moheimam.gif
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement