ExecuteMalware

2020-06-04 Misc IOCs

Jun 4th, 2020
3,811
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. GuLoader
  2. =========
  3. SUBJECTS OBSERVED
  4. SM-3417892309623.xls
  5.  
  6. SENDERS OBSERVED
  7. Travor Medlock <[email protected]>
  8.  
  9. MALDOC FILE HASHES
  10. SM-3417892309623.xls
  11. cecd8184636f7ee361a3477061927ee8
  12.  
  13. PAYLOAD FILE HASHES
  14. chrad.exe
  15. 0dc1627037b59a71aee7da5586443e7d
  16.  
  17. Hsix
  18. 01f141daf203cf24197cc9e2a563d519
  19.  
  20. GULOADER PAYLOAD DISTRIBUTION URLS FROM POWERSHELL/VB
  21. http://185.205.209.166/pftp/chrad.exe
  22. https://drive.google.com/u/0/uc?id=1nThFciVANTfNY2NEQai1E0FlGEeh3Z4W&export=download
  23. https://doc-0c-0o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/22a42b77ufshvf24nhqc295ng1bihj5q/1591295325000/03494046271176666289/*/1nThFciVANTfNY2NEQai1E0FlGEeh3Z4W?e=download
  24.  
  25. GULOADER C2
  26. 216.38.2.198:3360 (TCP)
  27.  
  28. Qakbot
  29. ======
  30. SUBJECTS OBSERVED
  31. Re: 1st data merchant services
  32. FW: Charges and Payments
  33.  
  34. SENDERS OBSERVED
  35.  
  36. MALDOC FILE HASHES
  37. KTEQ_6612_03062020.zip
  38. d7483ae2037a9a4151e3d72f63114784
  39.  
  40. Contains:
  41. KTEQ_749241244987_03062020.vbs
  42. c13a76771782466a13192107e1cf45b9
  43.  
  44. QAKBOT PAYLOAD FILE HASHES
  45. 8888888.png
  46. f535a7722df28598d46004fd7d86923d
  47.  
  48. PicturesViewer.exe
  49. 0493e5b9ac5faa3b6a125e8360613979
  50.  
  51. MALDOC DISTRIBUTION URLS
  52. http://truemansmoke.com/ddwbsfe/KTEQ_10363_03062020.zip
  53. https://pranaplanet.com/vpmhzmlqvmb/KTEQ_6612_03062020.zip
  54.  
  55. QAKBOT PAYLOAD DISTRIBUTION URLS
  56. http://wadebaverstock.com/jonxuyoz/8888888.png
Add Comment
Please, Sign In to add comment