G0dR4p3

Occamy_banking_01-08-2019

Aug 1st, 2019
224
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.07 KB | None | 0 0
  1. #Occamy #Banking #Trojan
  2. ------------------------------------------
  3. 01-08-2019
  4. ------------------------------------------
  5. Main object- "https://www.dropbox.com/s/n85rjj7xk4uz3di/PRINT4BC8.rar?dl=1"
  6. url https://www.dropbox.com/s/n85rjj7xk4uz3di/PRINT4BC8.rar?dl=1
  7. Dropped executable file
  8. sha256 C:\Users\admin\AppData\Local\Temp\Rar$EXa3128.48641\E9FB310E-036B-4A29-9163-BD69FA98E66E-4BC8_PlDF.exe 84ca2506fe6277410786da0cb73d0b9fc82e23725327e16aecac35987f3bfcdb
  9. sha256 C:\Users\admin\AppData\Roaming\PrjManDev.exe 91ea2e5f5b7573cff0baea7bc5b9d0796cfadee2fa3c6d48192a9982dca71fcc
  10. DNS requests
  11. domain www.dropbox.com
  12. domain accounts.google.com
  13. domain uc8389ee2e26c7e77ef3358ce117.dl.dropboxusercontent.com
  14. domain guimacdgt.tk
  15. domain guimacdgt.com
  16. domain guimacdgt.1s.fr
  17. Connections
  18. ip 162.125.66.1
  19. ip 162.125.66.6
  20. ip 2.16.106.203
  21. ip 66.96.147.96
  22. ip 88.221.164.202
  23. HTTP/HTTPS requests
  24. url http://guimacdgt.1s.fr/e.php?165
  25. url http://guimacdgt.1s.fr/e.php?105
  26. url http://guimacdgt.1s.fr/e.php?156
  27. url http://guimacdgt.1s.fr/e.php?62
Add Comment
Please, Sign In to add comment