Advertisement
G0dR4p3

Shade_troldesh_Ransomware_28-08-2019

Aug 28th, 2019
291
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.93 KB | None | 0 0
  1. #Shade #Troldesh #Ransomware
  2. ----------------------------------
  3. 28-08-2019 IOC's
  4. ----------------------------------
  5. Main object- "2019cd186b96e56bc1855676caf88a3c8ecf7c10b8e9e51be724a14c9233e253.bin.gz"
  6. sha256 9b18e25e5bd8f7567ada050d35429bc66327f13d818587af0612457f0be91997
  7. sha1 1ae0a516d368e805f21086d3c9c1ce86bf633f2e
  8. md5 94b3d3a79c0685a2bb4c71325c6b2d96
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\2c[1].jpg ad352e413c157e963315368c198d7fc64a95a2af40a69a91913e089e5840e58c
  11. DNS requests
  12. domain quickfingers.net
  13. domain ipv4bot.whatismyipaddress.com
  14. Connections
  15. ip 72.47.224.129
  16. ip 86.59.21.38
  17. ip 154.35.32.5
  18. ip 87.236.194.23
  19. ip 193.23.244.244
  20. ip 85.10.200.109
  21. ip 66.171.248.178
  22. ip 136.32.240.23
  23. HTTP/HTTPS requests
  24. url http://quickfingers.net/amfphp/browser/2c.jpg
  25. url http://ipv4bot.whatismyipaddress.com/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement