James_inthe_box

Corebot IOC's

Apr 6th, 2018
3,059
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.59 KB | None | 0 0
  1. Creates:
  2. C:\Users\<user>\AppData\Local\<40 bit hex>\container.dat <- encrypted, small
  3. C:\Users\<user>\AppData\Local\<40 bit hex>\<UUID>
  4.  
  5. Network:
  6. Connects to https://google.com
  7. Uses UA of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36" <-only seen with MITM
  8.  
  9. May attempt to c2 without querying DNS
  10. c2 traffic is https 443
  11. c2's at time of writing:
  12. 37.220.31.120:443
  13. 89.223.29.34:443
  14. 89.223.26.215:443
  15. checkbox.bit:443
  16.  
  17. Small activity footprint, does not appear to do much when using procmon or after executing for 2+ minutes.
Add Comment
Please, Sign In to add comment