Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #GandCrab #Ransomware V5.0.4
- ------------------------------------
- 04-01-2018 IOC's
- ------------------------------------
- Main object- "03ff2e69bb279a9380edd42822788dba2b509c8430e5ed6c004d8c20db775d0e.bin.gz"
- sha256 dd63125be7f7a531da209808d867da467b47d8949d2e391ddb4a270b1e04647b
- sha1 d5fefb868260553ea8ab0b7ff73759bbfe6e5312
- md5 c2e3ba704fb3a1a4e94f91576d47b704
- Dropped executable file
- sha256 C:\Users\admin\AppData\Local\Temp\494950006.exe bce4c97daa3ae1c1702046b2f8d7952ab076da8b6c9544331b08e76de21c005d
- sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\1[1].exe f018326456daf09fc5cab41e9254d6ff1e8320ffd74c87668ba60ab27a7a0cb7
- DNS requests
- domain www.haargenau.biz
- domain www.2mmotorsport.biz
- domain www.bizziniinfissi.com
- domain www.pizcam.com
- domain www.holzbock.biz
- domain www.fliptray.biz
- domain www.whitepod.com
- domain www.hotelweisshorn.com
- domain www.swisswellness.com
- domain www.belvedere-locarno.com
- domain www.hardrockhoteldavos.com
- domain www.seitensprungzimmer24.com
- domain seitensprungzimmer24.com
- domain www.morcote-residenza.com
- domain www.hrk-ramoz.com
- domain www.hotelfarinet.com
- domain www.bnbdelacolline.com
- domain www.aubergemontblanc.com
- domain www.arbezie-hotel.com
- domain www.alpenlodge.com
- domain www.arbezie.com
- domain www.aparthotelzurich.com
- domain www.torhotel.com
- domain elite-hotel.com
- domain www.hotelnationalzermatt.ch
- domain www.elite-hotel.com
- domain www.nationalzermatt.ch
- domain nationalzermatt.ch
- domain www.waageglarus.com
- domain www.bristol-adelboden.com
- domain www.nationalzermatt.com
- domain www.chambre-d-hote-chez-fleury.com
- domain www.hotelalbanareal.com
- domain www.mountainhostel.com
- domain www.apartmenthaus.com
- domain www.la-fontaine.com
- domain www.berginsel.com
- domain www.hotel-blumental.com
- domain www.limmathof.com
- domain bellevuewiesen.com
- domain www.luganohoteladmiral.com
- domain www.hotelgarni-battello.com
- domain www.hotel-zermatt.com
- domain www.hoteltruite.com
- domain www.geneva.frasershospitality.com
- domain www.seminarhotel.com
- domain www.bellevuewiesen.com
- domain www.kroneregensberg.com
- domain www.puurehuus.com
- domain www.eyholz.com
- domain www.stalden.com
- domain www.vignobledore.com
- domain www.schwendelberg.com
- domain www.hotelglanis.com
- domain www.hiexgeneva.com
- domain www.flemings-hotel.com
- domain www.nh-hotels.com
- domain www.petit-paradis.com
- domain www.berghaus-toni.com
- domain www.stchristophesa.com
- domain www.le-saint-hubert.com
- domain 16eme.com
- domain www.staubbach.com
- domain www.experimentalchalet.com
- domain www.16eme.com
- domain www.aubergecouronne.com
- domain www.guardagolf.com
- domain www.bonmont.com
- domain www.cm-lodge.com
- domain www.airporthotelbasel.com
- domain www.elite-biel.com
- domain www.samnaunerhof.com
- domain www.alimentarium.org
- domain www.hotellido-lugano.com
- domain guardagolf.com
- domain www.lassalle-haus.org
- domain www.vitatertia.org
- domain www.hotelchery.com
- domain www.ibis.com
- domain www.mercure.com
- domain www.hotelolden.com
- domain www.huusgstaad.com
- domain www.relais-crosets.com
- domain www.lerichemond.com
- domain www.hotelrotonde.com
- domain www.kreatifs.net
- domain www.lacommune.net
- domain www.disch.mehrmarken.net
- domain www.gemperle.net
- domain www.neuhof.org
- domain www.hoteldreirosen.net
- domain www.calisto.net
- domain www.dermann.org
- domain www.r-coiffure.net
- domain neuhof.org
- domain www.ueberland-garage.mehrmarken.net
- domain www.osteriadelcentro.net
- domain www.garage-schwyn.mehrmarken.net
- domain www.cantinesurcoux.net
- domain www.von-arx.net
- domain www.nett-coiffure.ch
- domain www.farbecht.net
- domain www.celi-vegas-avocats.net
- domain www.salon-coiffure-geneve.net
- domain www.haaratelier.net
- Connections
- ip 104.108.61.140
- ip 92.63.197.48
- ip 83.166.148.69
- ip 217.26.53.161
- ip 104.24.22.22
- ip 104.24.23.22
- ip 104.31.72.20
- ip 107.154.114.25
- ip 136.243.13.215
- ip 136.243.162.140
- ip 149.126.4.83
- ip 149.126.4.15
- ip 145.239.37.26
- ip 149.202.81.123
- ip 149.126.4.89
- ip 138.201.162.99
- ip 149.126.4.66
- ip 185.230.62.177
- ip 185.199.108.153
- ip 185.230.62.161
- ip 178.209.55.26
- ip 173.212.202.129
- ip 185.81.1.20
- ip 185.62.170.1
- ip 185.51.191.29
- ip 188.165.51.93
- ip 188.165.40.130
- ip 185.58.214.100
- ip 185.92.220.44
- ip 192.185.159.253
- ip 188.227.206.226
- ip 193.246.38.196
- ip 193.246.63.157
- ip 194.51.187.22
- ip 194.246.118.10
- ip 194.51.187.23
- ip 199.34.228.70
- ip 212.59.186.61
- ip 195.201.207.213
- ip 195.141.45.95
- ip 217.26.54.189
- ip 217.26.52.10
- ip 213.186.33.50
- ip 213.186.33.16
- ip 213.186.33.4
- ip 217.26.54.21
- ip 213.129.84.57
- ip 213.186.33.17
- ip 213.186.33.5
- ip 217.26.53.37
- ip 46.32.228.22
- ip 217.26.61.109
- ip 52.210.177.133
- ip 217.26.60.27
- ip 52.17.9.185
- ip 217.26.55.5
- ip 5.144.168.210
- ip 52.2.192.9
- ip 79.170.40.230
- ip 62.2.99.251
- ip 74.220.215.73
- ip 63.33.82.40
- ip 80.244.187.247
- ip 80.74.138.109
- ip 69.16.175.10
- ip 52.215.121.40
- ip 78.46.77.98
- ip 80.74.155.80
- ip 81.169.242.208
- ip 80.74.149.78
- ip 80.74.149.162
- ip 81.23.73.70
- ip 80.74.153.84
- ip 80.74.145.65
- ip 80.74.144.93
- ip 80.74.155.10
- ip 80.74.142.130
- ip 83.166.138.107
- ip 83.166.138.7
- ip 93.88.241.198
- ip 83.138.82.107
- ip 83.137.114.198
- ip 88.198.6.106
- ip 89.107.184.10
- ip 94.126.23.52
- ip 83.166.138.8
- ip 94.247.24.38
- HTTP/HTTPS requests
- url http://92.63.197.48/m/mb.exe
- url http://www.haargenau.biz/news/graphic/eshe.png
- url http://92.63.197.48/m/1.exe
- url http://92.63.197.48/m/3.exe
- url http://92.63.197.48/m/5.exe
- url http://92.63.197.48/m/2.exe
- url http://92.63.197.48/m/4.exe
- url http://www.pizcam.com/
- url http://www.2mmotorsport.biz/
- url http://www.haargenau.biz/
- url http://www.bizziniinfissi.com/
- url http://www.holzbock.biz/
- url http://www.bizziniinfissi.com/wp-content/tmp/derude.png
- url http://www.fliptray.biz/
- url http://www.holzbock.biz/uploads/imgs/semoke.gif
- url http://www.swisswellness.com/
- url http://www.hotelweisshorn.com/
- url http://www.hotelweisshorn.com/includes/tmp/dadaam.png
- url http://www.hrk-ramoz.com/uploads/image/setheszu.gif
- url http://www.whitepod.com/
- url http://www.belvedere-locarno.com/
- url http://www.morcote-residenza.com/
- url http://www.hrk-ramoz.com/
- url http://www.seitensprungzimmer24.com/
- url http://www.hardrockhoteldavos.com/
- url http://www.hotelfarinet.com/
- url http://www.aubergemontblanc.com/
- url http://www.torhotel.com/
- url http://www.aubergemontblanc.com/content/imgs/sosohe.jpg
- url http://www.torhotel.com/static/graphic/amzukezukezu.png
- url http://www.arbezie-hotel.com/
- url http://www.alpenlodge.com/
- url http://www.arbezie.com/data/pictures/ruim.jpg
- url http://www.bnbdelacolline.com/
- url http://www.aparthotelzurich.com/
- url http://www.limmathof.com/
- url http://www.berginsel.com/
- url http://www.chambre-d-hote-chez-fleury.com/
- url http://www.elite-hotel.com/
- url http://www.hotel-blumental.com/
- url http://www.waageglarus.com/static/images/moimhe.bmp
- url http://www.waageglarus.com/
- url http://www.nationalzermatt.com/
- url http://www.apartmenthaus.com/
- url http://www.bristol-adelboden.com/
- url http://www.bellevuewiesen.com/
- url http://www.luganohoteladmiral.com/
- url http://www.la-fontaine.com/static/images/esimhe.jpg
- url http://www.hoteltruite.com/includes/imgs/keesmeme.bmp
- url http://www.hotelalbanareal.com/
- url http://www.mountainhostel.com/
- url http://www.hotelgarni-battello.com/
- url http://www.seminarhotel.com/
- url http://www.la-fontaine.com/
- url http://www.hoteltruite.com/
- url http://www.hotelgarni-battello.com/wp-content/graphic/zuesimes.png
- url http://www.kroneregensberg.com/
- url http://www.schwendelberg.com/wp-content/pictures/thdaka.bmp
- url http://www.puurehuus.com/
- url http://www.stchristophesa.com/news/pictures/amme.gif
- url http://www.stchristophesa.com/
- url http://www.nh-hotels.com/
- url http://kroneregensberg.com/de/
- url http://www.stalden.com/
- url http://www.hotel-zermatt.com/
- url http://kroneregensberg.com/
- url http://www.vignobledore.com/
- url http://www.stalden.com/index.cfm
- url http://www.schwendelberg.com/
- url http://www.hotelglanis.com/content/image/dedahe.jpg
- url http://www.16eme.com/
- url http://www.staubbach.com/
- url http://www.berghaus-toni.com/includes/graphic/medarumo.jpg
- url http://www.flemings-hotel.com/
- url http://www.petit-paradis.com/
- url http://www.hotelglanis.com/
- url http://www.berghaus-toni.com/
- url http://www.eyholz.com/
- url http://www.petit-paradis.com/static/tmp/mozufuim.gif
- url http://www.hiexgeneva.com/
- url http://www.vignobledore.com/wp-content/images/demeso.bmp
- url http://www.samnaunerhof.com/
- url http://www.guardagolf.com/
- url http://www.cm-lodge.com/
- url http://www.airporthotelbasel.com/
- url http://www.le-saint-hubert.com/includes/imgs/immeke.bmp
- url http://guardagolf.com/
- url http://www.bonmont.com/news/tmp/fuhe.gif
- url http://www.aubergecouronne.com/
- url http://www.le-saint-hubert.com/
- url http://www.experimentalchalet.com/
- url http://www.bonmont.com/
- url http://www.elite-biel.com/
- url http://www.hotelchery.com/
- url http://www.hotelchery.com/static/imgs/ruruhe.bmp
- url http://www.vitatertia.org/
- url http://www.lerichemond.com/
- url http://www.neuhof.org/
- url http://www.mercure.com/
- url http://www.hotellido-lugano.com/
- url http://www.hotelolden.com/
- url http://www.ibis.com/
- url http://www.relais-crosets.com/
- url http://www.dermann.org/
- url http://www.huusgstaad.com/
- url http://www.lassalle-haus.org/
- url http://www.alimentarium.org/
- url http://www.hotelrotonde.com/
- url http://www.hoteldreirosen.net/
- url http://www.hoteldreirosen.net/content/graphic/kathka.png
- url http://www.hoteldreirosen.net/news/pics/momofuse.gif
- url http://www.lacommune.net/wp-content/pics/fuamseheeszu.jpg
- url http://www.lacommune.net/
- url http://www.cantinesurcoux.net/news/tmp/serufumo.png
- url http://www.disch.mehrmarken.net/
- url http://www.osteriadelcentro.net/
- url http://www.gemperle.net/
- url http://www.cantinesurcoux.net/
- url http://www.hoteldreirosen.net/data/images/imdaesseim.gif
- url http://www.salon-coiffure-geneve.net/
- url http://www.ueberland-garage.mehrmarken.net/
- url http://www.garage-schwyn.mehrmarken.net/
- url http://www.nett-coiffure.ch/
- url http://www.salon-coiffure-geneve.net/news/pics/hezu.gif
- url http://www.haaratelier.net/
- url http://www.farbecht.net/
- url http://www.calisto.net/
- url http://www.r-coiffure.net/
- url http://www.haaratelier.net/uploads/tmp/thkathde.bmp
- url http://www.kreatifs.net/
- url http://www.gemperle.net/static/tmp/sefumesoim.png
- url http://www.farbecht.net/content/image/mofurude.gif
- url http://www.nett-coiffure.ch/uploads/assets/imsoamdamo.bmp
- url http://www.von-arx.net/
- url http://www.celi-vegas-avocats.net/
- url http://www.von-arx.net/includes/graphic/sedade.jpg
- -------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement