Advertisement
MalwareMessiagh

Ursnif IOC

Jul 23rd, 2019
55,750
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.53 KB | None | 0 0
  1. Dropping URLs:
  2. http://gjdstephan13aa.com/sywo/fgoow.php?l=gihas[1-11].gxl
  3. http://pkzlionorberto.com/sywo/fgoow.php?l=gihas[1-11].gxl
  4. http://ttoneylii.net/sywo/fgoow.php?l=jylah[1-11].gxl
  5. http://h41iiellie65.net/sywo/fgoow.php?l=jylah[1-11].gxl
  6.  
  7. IPs:
  8. 109.196.164.79
  9. 23.106.125.24
  10. 23.106.125.239
  11. 45.129.2.110
  12. 85.143.223.225
  13.  
  14. Samples:
  15. https://app.any.run/tasks/a9bd3c93-3a09-410d-97a4-d9f1d0f28f91
  16. https://app.any.run/tasks/10dbc8c9-c8d2-405f-a5fb-427f6b145a09/
  17.  
  18. Update - was able to get working C2:
  19. prnaajm83[.]club
  20. 23.106.125.241
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement