ExecuteMalware

2020-06-04 Misc IOCs

Jun 4th, 2020
3,190
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. GuLoader
  2. =========
  3. SUBJECTS OBSERVED
  4. SM-3417892309623.xls
  5.  
  6. SENDERS OBSERVED
  7. Travor Medlock <travor@mtc-llc.com>
  8.  
  9. MALDOC FILE HASHES
  10. SM-3417892309623.xls
  11. cecd8184636f7ee361a3477061927ee8
  12.  
  13. PAYLOAD FILE HASHES
  14. chrad.exe
  15. 0dc1627037b59a71aee7da5586443e7d
  16.  
  17. Hsix
  18. 01f141daf203cf24197cc9e2a563d519
  19.  
  20. GULOADER PAYLOAD DISTRIBUTION URLS FROM POWERSHELL/VB
  21. http://185.205.209.166/pftp/chrad.exe
  22. https://drive.google.com/u/0/uc?id=1nThFciVANTfNY2NEQai1E0FlGEeh3Z4W&export=download
  23. https://doc-0c-0o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/22a42b77ufshvf24nhqc295ng1bihj5q/1591295325000/03494046271176666289/*/1nThFciVANTfNY2NEQai1E0FlGEeh3Z4W?e=download
  24.  
  25. GULOADER C2
  26. 216.38.2.198:3360 (TCP)
  27.  
  28. Qakbot
  29. ======
  30. SUBJECTS OBSERVED
  31. Re: 1st data merchant services
  32. FW: Charges and Payments
  33.  
  34. SENDERS OBSERVED
  35. tanveer@sofizar.com
  36.  
  37. MALDOC FILE HASHES
  38. KTEQ_6612_03062020.zip
  39. d7483ae2037a9a4151e3d72f63114784
  40.  
  41. Contains:
  42. KTEQ_749241244987_03062020.vbs
  43. c13a76771782466a13192107e1cf45b9
  44.  
  45. QAKBOT PAYLOAD FILE HASHES
  46. 8888888.png
  47. f535a7722df28598d46004fd7d86923d
  48.  
  49. PicturesViewer.exe
  50. 0493e5b9ac5faa3b6a125e8360613979
  51.  
  52. MALDOC DISTRIBUTION URLS
  53. http://truemansmoke.com/ddwbsfe/KTEQ_10363_03062020.zip
  54. https://pranaplanet.com/vpmhzmlqvmb/KTEQ_6612_03062020.zip
  55.  
  56. QAKBOT PAYLOAD DISTRIBUTION URLS
  57. http://wadebaverstock.com/jonxuyoz/8888888.png
Add Comment
Please, Sign In to add comment