ExecuteMalware

2020-04-24 Lokibot IOCs

Apr 24th, 2020
3,178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.71 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Overdue Balance// INV#2020-000185& 2020-000186
  3. Shipping Documents//change in the destination of your goods
  4.  
  5. SENDERS OBSERVED
  6.  
  7. EXCEL FILE HASHES
  8. DRAFT SHIPPING DOCUMENTS.xlsx
  9. 800043cbd22f836c2889c5558c3c9c8d
  10.  
  11. ferrandoemassone pymt slip.xlsx
  12. 9fb90898d3f455cac7c39c2d793fc8e2
  13.  
  14. PAYLOAD EXE FILE HASHES
  15. winlog.exe
  16. 77120727da31f18d9ad6944a063b7482
  17.  
  18. svchost.exe
  19. f7d1c25129ff84fd6e17a097e677e520
  20.  
  21. LOKIBOT PAYLOAD DISTRIBUTION URLS
  22. http://kung14wsdyeduationaldeveloperinvestmentt.duckdns.org/kungdoc/winlog.exe
  23. http://15wsdychneswealthandmoduleorganisationcv.duckdns.org/secure/svchost.exe
  24.  
  25. LOKIBOT C2
  26. http://avertonbullk.com/ig4/fre.php
Add Comment
Please, Sign In to add comment