Advertisement
paladin316

Vidar_IOCs_2019-11-25_14_02.txt

Nov 25th, 2019
1,535
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.93 KB | None | 0 0
  1. #Vidar #malware #OSINT #IOC
  2.  
  3. MD5s:
  4. 5ee1227e20fe723538b50b7025ee546e
  5. b51b126f69022c7f53b4e0c19608be39
  6. d9160e846a7dd1f58b972a5550999999
  7.  
  8. IPs:
  9. 161[.]117[.]225[.]32
  10. 208[.]95[.]112[.]1
  11. 209[.]141[.]33[.]126
  12. 23[.]52[.]1[.]137
  13. 23[.]52[.]1[.]152
  14. 23[.]52[.]1[.]160
  15. 47[.]254[.]232[.]105
  16. 62[.]210[.]6[.]175
  17.  
  18. Domains:
  19. bitbucket[.]org
  20. crarepo[.]com
  21. legion17[.]com
  22. pix-fix[.]net
  23. ssdupdate1[.]top
  24. ssdupdate2[.]top
  25. starlikespace[.]org
  26. superghost[.]ug
  27.  
  28. URL:
  29. http://bitbucket[.]org/being-decide/google/downloads/setup_c[.]exe,
  30. http://bitbucket[.]org/fastuploads/2019/downloads/setup_m[.]exe,
  31. http://bitbucket[.]org/teethdefinition/file/downloads/setup_c[.]exe,
  32. http://crarepo[.]com/,
  33. http://crarepo[.]com/237,
  34. http://crarepo[.]com/freebl3[.]dll,
  35. http://crarepo[.]com/freebl3[.]dll?ddosprotected=1,
  36. http://crarepo[.]com/mozglue[.]dll,
  37. http://crarepo[.]com/msvcp140[.]dll,
  38. http://crarepo[.]com/nss3[.]dll,
  39. http://crarepo[.]com/softokn3[.]dll,
  40. http://crarepo[.]com/vcruntime140[.]dll,
  41. http://legion17[.]com/legion17/welcome,
  42. http://pix-fix[.]net/p/wo[.]php?stub=24&cid=,
  43. http://ssdupdate1[.]top/gate1[.]php?a=bbed3e55656ghf02-0b41-11e3-8249id=2,
  44. http://ssdupdate1[.]top/gate1[.]php?a=bbed3e55656ghf02-0b41-11e3-8249id=28,
  45. http://ssdupdate1[.]top/gate1[.]php?a=true,
  46. http://ssdupdate2[.]top/test/eu/1[.]exe,
  47. http://ssdupdate2[.]top/test/eu/2[.]exe,
  48. http://ssdupdate2[.]top/test/us/1[.]exe,
  49. http://ssdupdate2[.]top/test/us/2[.]exe,
  50. http://starlikespace[.]org/,
  51. http://starlikespace[.]org/237,
  52. http://starlikespace[.]org/83,
  53. http://starlikespace[.]org/freebl3[.]dll,
  54. http://starlikespace[.]org/freebl3[.]dll?ddosprotected=1,
  55. http://starlikespace[.]org/mozglue[.]dll,
  56. http://starlikespace[.]org/msvcp140[.]dll,
  57. http://starlikespace[.]org/nss3[.]dll,
  58. http://starlikespace[.]org/softokn3[.]dll,
  59. http://starlikespace[.]org/vcruntime140[.]dll,
  60. http://superghost[.]ug/api/check[.]get,
  61. http://superghost[.]ug/api/gate[.]get?p1=0&p2=9&p3=0&p4=0&p5=0&p6=0&p7=0&p8=0&p9=0&p10=gIBmoBIFHT6Ix0AKSoc+DvHPbaNDkQqeETPp,
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement