Advertisement
G0dR4p3

Shade_Troldesh_Ransomware_IOCs_31-07-2019

Jul 31st, 2019
271
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.00 KB | None | 0 0
  1. #Shade #Troldesh #Ransmoware
  2. ----------------------------------
  3. 31-07-2019
  4. ----------------------------------
  5. Main object- "36a1d9dae56f1fcdd86ef4b5afb7b222c09c19e23eb7066d6f6b44328a8cd376.bin.gz"
  6. sha256 6d48f84b44c8789bb97b1e8d4fac4d35e6ed7ae5d6f84174ead522c3dc8fb180
  7. sha1 793911941dde1cf97e327189678306884c7b847f
  8. md5 c2f2e45417702f8339076130b4f02864
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\1c[1].jpg e4da415068c83a1710c3eda4818cb6a990a0405c123d32e9b78daea10d04fc92
  11. DNS requests
  12. domain whatismyipaddress.com
  13. domain www.bdtkd.co.uk
  14. domain whatsmyip.net
  15. Connections
  16. ip 109.203.124.201
  17. ip 194.109.206.212
  18. ip 154.35.32.5
  19. ip 212.51.129.49
  20. ip 173.249.8.113
  21. ip 86.59.21.38
  22. ip 217.79.179.177
  23. ip 104.16.155.36
  24. ip 104.18.34.131
  25. HTTP/HTTPS requests
  26. url http://www.bdtkd.co.uk/wp-content/themes/bluestreet/customizer/1c.jpg
  27. url http://whatismyipaddress.com/
  28. url http://whatsmyip.net/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement