MalwareMessiagh

Ursnif IOC

Jul 2nd, 2019
51,989
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.67 KB | None | 0 0
  1. Dropping domains:
  2. koe32dayton.com/sp282y/si2s81-19.php?l=gwoir[1-12].pem
  3. g69jylv.xyz/sp282y/si2s81-19.php?l=gwoir[1-12].pem
  4. sdelaneyuaclotilde.club/sp282y/si2s81-19.php?l=kweql[1-12].pem
  5. zuvwax.com/sp282y/si2s81-19.php?l=nbotil[1-12].pem
  6. migraconex.net/wp-content/uploads/2019/06/iasbd187232[.]rar
  7.  
  8. C2:
  9. vr9519.club
  10. tjanisiu.club
  11. j32uqicm.info
  12. syoshikodelmerlance.club
  13. dmargieieiyoq.top
  14. woa79ewinfield.club
  15. w3438e49rodolfo.info
  16.  
  17. IPs:
  18. 5.39.119.175
  19. 46.29.165.248
  20. 51.83.52.180
  21. 85.143.220.30
  22. 85.143.221.165
  23. 89.223.90.229
  24. 92.63.105.244
  25. 94.103.80.22
  26. 109.234.38.142
  27. 185.193.141.220
  28. 185.174.172.96
  29. 185.193.141.241
  30. 185.193.141.234
  31. 194.87.103.80
  32. 212.109.194.97
Add Comment
Please, Sign In to add comment