Advertisement
secresearcher

Necurs botnet - Locky and Trickbot

Sep 28th, 2017
391
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.00 KB | None | 0 0
  1. Trickbot - group_tag - mac1
  2. http://ambrogiauto.com/9hciunery8g
  3. http://autoecoleathena.com/9hciunery8g
  4. http://autoecoleboisdesroches.com/9hciunery8g
  5. http://autoecole-jeanpierre.com/9hciunery8g
  6. http://camerawind.com/9hciunery8g
  7. http://conlin-boats.com/9hciunery8g
  8. http://feng-lian.com.tw/9hciunery8g
  9. http://flooringforyou.co.uk/9hciunery8g
  10. http://fls-portal.co.uk/9hciunery8g
  11. http://fmarson.com/9hciunery8g
  12. http://freevillemusic.com/9hciunery8g
  13. http://geeks-online.de/9hciunery8g
  14. http://givensplace.com/9hciunery8g
  15. http://jakuboweb.com/9hciunery8g
  16. http://jaysonmorrison.com/9hciunery8g
  17. http://melting-potes.com/9hciunery8g
  18. http://patrickreeves.com/9hciunery8g
  19. https://www.virustotal.com/#/file/01e771dc6cf9572eac3d87120d7a7d1ff95fdc1499b668c7fde2919e0f685256/detection
  20.  
  21. Locky
  22. http://americanbulldogradio.com/LUYTbjnrf
  23. http://anarakdesert.com/LUYTbjnrf
  24. http://asnsport-bg.com/LUYTbjnrf
  25. http://astilleroscotnsa.com/LUYTbjnrf
  26. http://atlantarecyclingcenters.com/LUYTbjnrf
  27. http://augustinechua.com/LUYTbjnrf
  28. http://classactionlawsuitnewscenter.com/LUYTbjnrf
  29. http://davidstephensbanjo.com/LUYTbjnrf
  30. http://essenza.co.id/LUYTbjnrf
  31. http://evlilikpsikolojisi.com/LUYTbjnrf
  32. http://e-westchesterpropertytax.com/LUYTbjnrf
  33. http://felicesfiestas.com.mx/LUYTbjnrf
  34. http://financeforautos.com/LUYTbjnrf
  35. http://fincasoroel.es/LUYTbjnrf
  36. http://kailanisilks.com/LUYTbjnrf
  37. http://mediatrendsistem.com/LUYTbjnrf
  38. http://modaintensa.com/LUYTbjnrf
  39. http://mtblanc-let.co.uk/LUYTbjnrf
  40. http://plumanns.com/LUYTbjnrf
  41. https://www.virustotal.com/#/file/4a4491a5daa0b8c0d4e694601cbb860e0e069356b83e2f6ea215be758f533f1e/detection
  42.  
  43. Locky with different hash
  44. http://poemsan.info/p66/d8743fgh
  45. https://www.virustotal.com/#/file/3e55a7a405e4c4e4ad6d19296ac512d6c32441d5a65419cd116faa672b11963c/detection
  46.  
  47. Ran the script and it is installing Locky in AU because geeks-online URL is not responding. Therefore, based on script countries GB, UK, AU, BE, IE and LU are targeted with Trickbot and if that doesn't work it will infect with ransomware.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement