Advertisement
G0dR4p3

Shade_Ransomware_IOCs_17-01-2019

Jan 17th, 2019
574
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.82 KB | None | 0 0
  1. #Shade #Troldesh #Ransomware
  2. ---------------------------------
  3. 17-01-2019 IOC's
  4. ---------------------------------
  5. Main object- "rasy.jpg"
  6. url http://epifaniacr.net/rasy.jpg
  7. sha256 cbcc00905b93912dc6c51fc8913e5a7d105f7cd4b98a7ffa7da1f0d2c4f172f5
  8. sha1 a3c6c1153952b9ed50db06fb0aed44b97454a142
  9. md5 5eed3d7625e01c2d1196f6ca6a0fefeb
  10. DNS requests
  11. domain whatsmyip.net
  12. domain whatismyipaddress.com
  13. Connections
  14. ip 195.138.255.24
  15. ip 104.16.20.96
  16. ip 208.83.223.34
  17. ip 104.18.34.131
  18. ip 148.251.11.21
  19. ip 131.188.40.189
  20. ip 62.210.83.207
  21. ip 85.229.85.213
  22. ip 86.59.21.38
  23. HTTP/HTTPS requests
  24. url http://whatismyipaddress.com/
  25. url http://whatsmyip.net/
  26. -----------------------------------------
  27. **RANSOMNOTE**
  28. -----------------------------------------
  29. All the important files on your computer were encrypted.
  30. To decrypt the files you should send the following code:
  31. 906D0F2E2F604F839E04|0
  32. to e-mail address Novikov.Vavila@gmail.com .
  33. Then you will receive all necessary instructions.
  34. All the attempts of decryption by yourself will result only in irrevocable loss of your data.
  35. If you still want to try to decrypt them by yourself please make a backup at first because
  36. the decryption will become impossible in case of any changes inside the files.
  37. If you did not receive the answer from the aforecited email for more than 48 hours (and only in this case!),
  38. use the feedback form. You can do it by two ways:
  39. 1) Download Tor Browser from here:
  40. https://www.torproject.org/download/download-easy.html.en
  41. Install it and type the following address into the address bar:
  42. http://cryptsen7fo43rr6.onion/
  43. Press Enter and then the page with feedback form will be loaded.
  44. 2) Go to the one of the following addresses in any browser:
  45. http://cryptsen7fo43rr6.onion.to/
  46. http://cryptsen7fo43rr6.onion.cab/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement