Advertisement
G0dR4p3

Another_GandCrab_Ransomware_IOC's_09-05-2018

May 9th, 2018
339
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. #GandCrab #Ransomware
  2. ------------------------------
  3. 09-05-2018 IOC's
  4. ------------------------------
  5. Main object- "new 7.txt"
  6. sha256 ddbe6a4def6201f9e82ceeba817b0fedbae3e898d3b1a026b649f217fd5fe24f
  7. sha1 ab40588f2a84a8e6ced338740cd1d378069f502d
  8. md5 9de7c4816311ee67e711d3ee1bf9064f
  9. Dropped executable file
  10. sha256 C:\Users\admin\Downloads\1.pdf a383cc821d58c21466acbb16171c972093a7a6db8646c716ca3b9b710b4d197b
  11. sha256 C:\Users\admin\AppData\Roaming\Microsoft\vyavdq.exe 016183d77ae3700d97bf8d876fe1b30116a63c96bb01b423a87773c9355f59da
  12. DNS requests
  13. domain carder.bit
  14. domain ns2.wowservers.ru
  15. domain ns1.wowservers.ru
  16. domain ipv4bot.whatismyipaddress.com
  17. domain www.xdhcf.com
  18. Connections
  19. ip 94.249.60.127
  20. ip 189.75.183.21
  21. ip 47.104.174.54
  22. ip 66.171.248.178
  23. ip 172.217.22.34
  24. HTTP/HTTPS requests
  25. url http://www.xdhcf.com/update.php
  26. url http://carder.bit/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement