G0dR4p3

Shade_Troldesh_Ransomware_IOCs_19-07-2019

Jul 19th, 2019
223
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.95 KB | None | 0 0
  1. #Shade #Troldesh #Ransomware
  2. ------------------------------------
  3. 19-07-2019
  4. ------------------------------------
  5. Main object- "a9ff0707063866fc955f90af8a98ad410ec9836a791115d3f997a6c01595532c.bin.gz"
  6. sha256 65efc840b5da7b5000e748a4bf76866d7926e13a229bf6761cd43a540203f525
  7. sha1 85f7aa58f3fe340a0a94914bad11d8249a85c071
  8. md5 db0cc9532d04dbe807f17667501cbd87
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\1c[1].jpg efc8a598d15f50646444551c6ff08cea8c3a173f307ecc0b42aaa94d043fba3a
  11. DNS requests
  12. domain whatismyipaddress.com
  13. domain ecoteh.fund
  14. domain whatsmyip.net
  15. Connections
  16. ip 195.208.1.167
  17. ip 128.31.0.39
  18. ip 194.109.206.212
  19. ip 158.58.170.183
  20. ip 142.54.162.114
  21. ip 91.250.84.156
  22. ip 104.16.154.36
  23. ip 104.18.35.131
  24. HTTP/HTTPS requests
  25. url http://ecoteh.fund/errordocs/style/1c.jpg
  26. url http://whatismyipaddress.com/
  27. url http://whatsmyip.net/
Add Comment
Please, Sign In to add comment