Advertisement
G0dR4p3

Formbook_Trojan_IoCs_02-10-2019

Oct 2nd, 2019
314
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.33 KB | None | 0 0
  1. #Formbook #Trojan
  2. --------------------------------
  3. 02-10-2019
  4. --------------------------------
  5. Main object- "zomdoz.png"
  6. url http://www.csday.site/pure/zomdoz.png
  7. sha256 9e68391284fca66246676fedc610e54abda9f00546a9ea3b2c20ba2ccc7dd35b
  8. sha1 d430f7d5af736b972af9a7c42d622e67a59daf7e
  9. md5 8a84bfe1d301790d1e0b3d91d2e588eb
  10. DNS requests
  11. domain sltnet.in
  12. domain art-offers.online
  13. domain lafourmi83.net
  14. domain robertsrenovation.com
  15. domain xifancode.com
  16. domain baihuirsj.com
  17. domain segestavacanze.com
  18. Connections
  19. ip 176.223.132.209
  20. ip 153.92.6.144
  21. ip 23.107.185.242
  22. ip 195.110.124.154
  23. HTTP/HTTPS requests
  24. url http://sltnet.in/cm/js/main/
  25. url http://sltnet.in/cm/js/main/?-ZLTih=7hjPjCNMLSiGeceoAqz5CI4+67EVvuVkdW26WVPMIHlGGwX4gyEXHqD9Qa3gnHJyAa9oQg==&2d=llzDUf
  26. url http://robertsrenovation.com/cm/js/main/?-ZLTih=7NgeOCO6O4slzXvhqRkTRo/Vo0fVL/3CL/t3vpSDuYPycxlJvSfm4cWrUhgkskafYLgLDw==&2d=llzDUf&sql=1
  27. url http://robertsrenovation.com/cm/js/main/
  28. url http://segestavacanze.com/cm/js/main/?-ZLTih=Ap0mW10VhOl3I2IWaix4e6uPFq71JLgNXQsRRYdJQEJWnQkY0rHE2KWrrYj6O8jbum4sSA==&2d=llzDUf&sql=1
  29. url http://segestavacanze.com/cm/js/main/
  30. url http://baihuirsj.com/cm/js/main/
  31. url http://baihuirsj.com/cm/js/main/?-ZLTih=BlrIIo7IKcEvQSCgk8MZJENtSBXZekSj13Iduzpcl3J+4ztXdwUs9Je24z4q5lwrVcpA5Q==&2d=llzDUf&sql=1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement