Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Gozi #Ursnif #Malware
- -----------------------------
- 09-05-2018 IOC's
- -----------------------------
- Main object- "kuuu.yarn"
- url http://dqowndqwnd.net/lipomargara/kuuu.yarn
- sha256 1feca4cb089689a4bc54589a58dd0521dd0c79e1acea3c9c664d583e5d0f0bcc
- sha1 d8f028d06027718ff4d5d18a22d225e9bbd2fe0a
- md5 45392b4744a8312da010ab12c3257bdb
- DNS requests
- domain exhibitorsuccess.com
- domain htirt8h1thr48th.net
- domain myip.opendns.com
- domain resolver1.opendns.com
- Connections
- ip 208.67.222.222
- ip 204.44.121.60
- ip 93.184.221.240
- ip 143.95.151.144
- HTTP/HTTPS requests
- url http://exhibitorsuccess.com/img/internet_explorer/ku.rar
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement