Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Qakbot spx139 spun up around 14:24 UTC.
- It looks like its distroing zloader -> Qakbot again, also, the vbs directly drops zloader after a period of time.
- vbs name:ATTN_54585_06112020.vbs
- zloader C2s:
- https://xeemoquo.top/treusparq.php
- https://leeephee.top/treusparq.php
- https://withifceale.top/treusparq.php
- https://wpsnoum.pw/treusparq.php
- https://wsaexdig.pw/treusparq.php
- Qakbot Download: http://cccommercialcleaning.com.au/wp-content/themes/twentyfifteen/1/spx139/*.exe (probably dasfdsfsdf.exe)
- Qakbot IPs:
- 98.16.204.189:995
- 88.158.199.95:443
- 24.102.235.160:995
- 96.18.240.158:443
- 67.165.206.193:995
- 81.103.144.77:443
- 184.180.157.203:2222
- 47.136.224.60:443
- 104.221.4.11:2222
- 203.33.138.230:443
- 72.204.242.138:20
- 75.137.239.211:443
- 74.215.201.122:443
- 41.228.201.162:443
- 92.29.5.162:995
- 108.30.125.94:443
- 207.255.161.8:2078
- 173.172.205.216:443
- 68.134.181.98:443
- 5.12.50.241:443
- 41.129.128.231:443
- 89.247.216.59:443
- 59.95.84.255:443
- 24.229.245.124:995
- 98.114.185.3:443
- 207.255.18.67:443
- 108.49.221.180:443
- 86.125.140.0:2222
- 86.127.24.61:21
- 216.229.92.42:443
- 24.228.7.174:443
- 144.202.48.107:443
- 207.246.71.122:443
- 45.77.215.141:443
- 108.28.90.129:443
- 75.182.220.196:2222
- 86.233.4.153:2222
- 111.251.66.160:443
- 5.12.111.88:443
- 151.73.124.242:443
- 82.77.169.118:2222
- 81.133.234.36:2222
- 117.199.6.72:443
- 35.143.248.234:443
- 201.209.4.83:2078
- 82.37.242.8:443
- 84.232.238.30:443
- 24.164.79.147:443
- 80.14.209.42:2222
- 100.38.123.22:443
- 66.68.22.151:443
- 46.214.86.217:443
- 77.237.184.66:995
- 5.107.232.32:2222
- 70.168.130.172:443
- 96.56.237.174:990
- 79.116.229.37:443
- 118.168.236.225:443
- 79.115.254.172:443
- 86.4.44.48:443
- 24.27.82.216:2222
- 69.40.17.142:443
- 95.77.144.238:443
- 104.235.90.116:443
- 68.200.23.189:443
- 72.204.242.138:53
- 85.121.42.12:995
- 72.29.181.77:2078
- 24.122.228.88:443
- 216.229.92.42:995
- 67.83.54.76:2222
- 24.122.157.93:443
- 72.190.101.70:443
- 74.134.46.7:443
- 71.187.170.235:443
- 85.186.50.42:443
- 68.46.142.48:443
- 24.43.22.220:993
- 74.75.216.202:443
- 100.4.173.223:443
- 75.81.25.223:443
- 74.135.37.79:443
- 1.40.42.4:443
- 66.208.105.6:443
- 173.175.29.210:443
- 89.35.93.254:2222
- 81.245.66.237:995
- 199.247.16.80:443
- 80.240.26.178:443
- 199.247.22.145:443
- 216.201.162.158:995
- 178.223.17.74:995
- 72.240.245.253:443
- 70.174.3.241:443
- 47.203.42.163:443
- 72.204.242.138:50003
- 50.244.112.10:443
- 24.43.22.220:995
- 72.204.242.138:80
- 72.204.242.138:443
- 2.190.200.253:443
- 69.11.247.242:443
- 76.187.8.160:443
- 184.98.104.7:995
- 66.26.160.37:443
- 188.192.75.8:443
- 134.0.196.46:995
- 72.204.242.138:32100
- 65.131.83.170:995
- 75.183.135.48:443
- 72.16.212.108:465
- 77.159.149.74:443
- 200.113.201.83:993
- 72.204.242.138:6881
- 76.170.77.99:443
- 47.153.115.154:995
- 185.246.9.69:995
- 67.250.184.157:443
- 47.146.169.85:443
- 96.37.137.42:443
- 67.209.195.198:3389
- 74.56.167.31:443
- 68.4.137.211:443
- 189.236.218.181:443
- 47.41.3.40:443
- 207.255.161.8:443
- 73.214.248.17:995
- 96.56.237.174:993
- 100.40.48.96:443
- 79.113.215.51:443
- 98.118.156.172:443
- 70.183.127.6:995
- 50.104.68.223:443
- 24.201.79.208:2078
- 72.204.242.138:443
- 184.90.139.176:2222
- 24.202.42.48:2222
- 172.242.156.50:995
- 108.54.205.207:443
- 24.42.14.241:995
- 42.3.8.102:443
- 188.27.6.170:443
- 74.193.197.246:443
- 68.174.15.223:443
- 184.96.155.4:993
- 98.115.138.61:443
- 75.87.161.32:995
- 207.162.184.228:443
- 137.99.224.198:443
- 178.27.203.107:443
- Mirror: https://ghostbin.co/paste/ywhs4
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement