Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sample 01de124cfce46ee08b17cee79487f63a (https://app.any.run/tasks/95c6675b-1cb6-460b-a9b7-e26dad19f760)
- -PONY FAREIT TROJAN
- -Downloaded from: hxxp://selfhelpstartshere.]com/wp-admin/q.exe (https://urlhaus.abuse.ch/url/206165/)
- -Urls into the unpacked binary:
- hxxp://theeditedword.com/wp-includes/art.exe - 9ae9ef73266e59f9a867ada98181b2c3 #COBALSTRIKE #LOADER
- hxxp://ikusi.org/wp-content/plugins/apikey/art.exe - 9ae9ef73266e59f9a867ada98181b2c3 #COBALSTRIKE #LOADER
- hxxp://avans24.ru/art.exe - 9ae9ef73266e59f9a867ada98181b2c3 #COBALSTRIKE #LOADER
- hxxp://cid.ag/wp-admin/art.exe - 9ae9ef73266e59f9a867ada98181b2c3 #COBALSTRIKE #LOADER
- hxxp://kingusaref.com/mlu/forum.php
- hxxp://tansinmaked.ru/mlu/forum.php
- hxxp://retnejustren.ru/mlu/forum.php
- Sample 9ae9ef73266e59f9a867ada98181b2c3 (https://app.any.run/tasks/be2ce0d5-1ffc-4c03-b52a-0223c05d773d)
- -COBALTSTRIKE LOADER
- -Connects to:
- http://31.44.184.33/H7mp (https://app.any.run/tasks/80fbc913-c3a2-413b-9bb5-9a37a647ea0c)
- http://31.44.184.33/g.pixel
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement