MalwareQuinn

QakbotIOCS_04_22_2020

Apr 22nd, 2020
1,287
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Qakbot IOCs:
  2. Distro spun up around 11:30 GMT
  3.  
  4. spx102 distribution: VBS
  5.  
  6. URLs:
  7. http://hasumvina.nrglobal.top/wp-content/themes/mapro/pump/55555.png
  8. http://4mco.com.pk/wp/wp-content/themes/mapro/pump/55555.png
  9. http://cloud.wmsinfo.com.br/wordpress/wp-content/themes/mapro/pump/55555.png
  10. http://jeromenetpanel.ml/wp-content/themes/mapro/pump/55555.png
  11. http://cheshirecheetah.com/wp-content/themes/mapro/pump/55555.png
  12.  
  13. No EXE yet.
  14.  
  15. https://app.any.run/tasks/a5926128-c8dd-4a1e-8a40-1648e1ab1d59
  16.  
  17. Exe went out
  18. IPs:
  19.  
  20. 68.1.171.93:443
  21. 98.213.28.175:443
  22. 31.5.189.71:443
  23. 75.81.25.223:995
  24. 86.106.126.91:443
  25. 216.201.162.158:443
  26. 80.14.209.42:2222
  27. 86.122.254.67:2222
  28. 98.26.50.62:995
  29. 197.166.90.151:443
  30. 71.58.21.235:443
  31. 78.96.177.188:443
  32. 73.137.187.150:443
  33. 188.173.185.139:443
  34. 46.214.136.6:443
  35. 86.124.227.238:443
  36. 104.36.135.227:443
  37. 76.111.128.194:443
  38. 81.245.66.237:995
  39. 71.220.222.169:443
  40. 50.247.230.33:995
  41. 216.163.4.91:443
  42. 24.168.237.215:443
  43. 70.124.29.226:443
  44. 68.60.221.169:465
  45. 86.189.181.83:443
  46. 2.179.27.180:443
  47. 108.185.113.12:443
  48. 46.153.115.228:995
  49. 176.100.2.192:443
  50. 201.209.218.89:2078
  51. 186.135.122.22:443
  52. 72.16.57.99:443
  53. 65.131.79.162:995
  54. 67.6.34.43:443
  55. 73.94.229.115:443
  56. 173.3.132.17:995
  57. 24.229.245.124:995
  58. 67.165.206.193:995
  59. 68.39.177.147:995
  60. 72.80.137.215:443
  61. 47.203.89.185:443
  62. 68.14.210.246:22
  63. 74.135.85.117:443
  64. 188.25.93.215:443
  65. 100.1.239.189:443
  66. 152.32.80.37:443
  67. 71.74.12.34:443
  68. 69.92.54.95:995
  69. 148.75.231.53:443
  70. 72.142.106.198:995
  71. 86.124.1.76:443
  72. 47.222.40.131:443
  73. 62.121.78.22:443
  74. 94.53.92.42:443
  75. 71.69.128.2:2222
  76. 168.103.52.51:995
  77. 72.218.167.183:995
  78. 89.43.136.239:443
  79. 96.255.188.58:443
  80. 202.161.126.168:443
  81. 76.172.59.56:2222
  82. 206.183.190.53:995
  83. 212.126.109.14:443
  84. 50.246.229.50:443
  85. 47.40.244.237:443
  86. 24.210.45.215:443
  87. 24.44.180.236:2222
  88. 100.38.123.22:443
  89. 72.204.242.138:443
  90. 72.16.212.107:465
  91. 110.142.205.182:443
  92. 70.126.76.75:443
  93. 100.40.48.96:443
  94. 46.214.62.199:443
  95. 181.126.86.223:443
  96. 73.169.47.57:443
  97. 72.204.242.138:53
  98. 72.204.242.138:50003
  99. 108.54.103.234:443
  100. 68.98.142.248:443
  101. 24.115.246.224:995
  102. 75.82.228.209:443
  103. 93.26.180.87:443
  104. 58.177.238.186:443
  105. 89.34.231.30:443
  106. 120.147.67.62:2222
  107. 72.78.198.100:443
  108. 72.204.242.138:443
  109. 76.180.69.236:443
  110. 209.182.121.133:2222
  111. 5.182.39.156:443
  112. 47.136.224.60:443
  113. 108.227.161.27:995
  114. 203.33.139.134:443
  115. 72.209.191.27:443
  116. 5.193.175.12:2078
  117. 68.82.125.234:443
  118. 86.126.219.246:443
  119. 104.235.116.15:443
  120. 76.187.97.98:2222
  121. 95.77.144.238:443
  122. 184.180.157.203:2222
  123. 76.187.8.160:443
  124. 97.127.144.203:2222
  125. 207.255.158.180:443
  126. 98.22.66.236:443
  127. 137.99.224.198:443
  128. 67.250.184.157:443
  129. 96.236.225.10:443
  130. 24.55.152.50:995
  131. 50.104.67.101:443
  132. 173.172.205.216:443
  133. 50.244.112.106:443
  134. 187.163.101.137:995
  135. 72.204.242.138:443
  136. 96.35.170.82:2222
  137. 47.205.231.60:443
  138. 79.113.219.121:443
  139. 73.214.231.2:443
  140. 67.209.195.198:3389
  141. 47.146.169.85:443
  142. 47.214.144.253:443
  143. 89.45.111.127:443
  144. 72.204.242.138:993
  145. 75.87.161.32:995
  146. 108.30.161.143:443
  147. 72.132.249.144:995
  148. 67.131.59.17:443
  149. 24.201.79.208:2078
  150. 50.108.212.180:443
  151. 5.13.126.243:443
  152. 73.23.194.75:443
  153. 75.110.250.89:443
  154. 68.134.181.98:443
  155. 73.60.156.223:443
  156. 81.103.144.77:443
  157. 94.176.128.176:443
  158. 89.137.162.193:443
  159. 98.118.156.172:443
  160. 118.93.167.173:2222
  161. 86.125.208.132:443
  162. 174.34.67.106:2222
  163. 85.154.102.243:443
  164. 121.121.119.6:443
  165. 176.223.114.79:443
  166. 76.15.41.32:443
  167. 79.119.69.76:443
  168. 98.23.52.168:22
  169. 46.214.139.214:443
RAW Paste Data