Advertisement
MalwareQuinn

Qakbot_06_09_2020

Jun 9th, 2020
12,003
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.06 KB | None | 0 0
  1. Qakbot spx136 distro spun up around 14:00 UTC. The dropper for today did not have the 6 URLS inside, but instead dropped the exe onto the system.
  2.  
  3. VBS Name: AGRM_2675923_06082020.vbs
  4.  
  5. IPs:
  6.  
  7. 184.180.157.203:2222
  8. 47.136.224.60:443
  9. 5.13.97.215:995
  10. 73.101.211.117:443
  11. 104.221.4.11:2222
  12. 203.33.139.134:443
  13. 151.73.124.242:443
  14. 76.111.128.194:443
  15. 72.209.191.27:443
  16. 64.19.74.29:995
  17. 72.204.242.138:990
  18. 45.45.51.182:2222
  19. 173.22.120.11:2222
  20. 75.183.135.48:443
  21. 81.245.66.237:995
  22. 188.27.68.239:443
  23. 207.255.161.8:2078
  24. 199.247.22.145:443
  25. 76.187.8.160:443
  26. 173.172.205.216:443
  27. 108.30.125.94:443
  28. 66.208.105.6:443
  29. 207.255.161.8:32103
  30. 50.29.181.193:995
  31. 200.75.136.78:443
  32. 108.39.93.45:443
  33. 199.247.16.80:443
  34. 149.71.50.158:443
  35. 47.222.40.131:443
  36. 79.119.67.149:443
  37. 185.246.9.69:995
  38. 65.96.36.157:443
  39. 88.201.103.165:443
  40. 108.54.205.207:443
  41. 178.168.50.66:443
  42. 5.14.59.85:443
  43. 81.103.144.77:443
  44. 217.162.149.212:443
  45. 67.246.16.250:995
  46. 73.226.220.56:443
  47. 5.13.99.38:995
  48. 31.5.26.171:443
  49. 108.28.90.129:443
  50. 188.27.6.170:443
  51. 70.183.127.6:995
  52. 98.114.185.3:443
  53. 50.104.68.223:443
  54. 72.28.255.159:995
  55. 5.15.32.225:443
  56. 36.77.151.211:443
  57. 82.178.48.65:443
  58. 140.82.21.191:443
  59. 98.32.60.217:443
  60. 47.146.169.85:443
  61. 75.110.250.89:443
  62. 35.142.12.163:2222
  63. 76.169.33.226:443
  64. 75.183.171.155:3389
  65. 96.37.137.42:443
  66. 67.209.195.198:3389
  67. 80.195.103.146:2222
  68. 74.56.167.31:443
  69. 76.86.57.179:2222
  70. 216.201.162.158:995
  71. 71.185.60.227:443
  72. 86.126.117.54:995
  73. 49.191.4.245:443
  74. 188.209.108.87:2222
  75. 217.66.244.183:443
  76. 103.110.49.88:443
  77. 79.117.161.67:21
  78. 42.3.8.102:443
  79. 178.87.254.174:443
  80. 24.201.79.208:2078
  81. 72.204.242.138:443
  82. 86.126.97.183:2222
  83. 74.135.37.79:443
  84. 2.45.53.40:2222
  85. 79.115.152.163:443
  86. 184.96.155.4:993
  87. 70.168.130.172:443
  88. 188.26.249.181:443
  89. 101.108.115.107:443
  90. 68.174.15.223:443
  91. 98.115.138.61:443
  92. 82.77.169.118:2222
  93. 75.87.161.32:995
  94. 41.231.234.147:443
  95. 67.250.184.157:443
  96. 207.162.184.228:443
  97. 189.231.198.212:443
  98. 96.56.237.174:993
  99. 97.93.211.17:443
  100. 47.138.200.85:443
  101. 72.204.242.138:50001
  102. 182.181.39.40:995
  103. 190.198.124.212:2078
  104. 72.36.59.46:2222
  105. 96.35.170.82:2222
  106. 173.3.132.17:995
  107. 76.30.66.244:443
  108. 69.246.151.5:995
  109. 68.49.120.179:443
  110. 69.92.54.95:995
  111. 50.244.112.10:443
  112. 197.165.220.106:443
  113. 207.255.161.8:32102
  114. 66.222.88.126:995
  115. 108.58.9.238:995
  116. 47.152.210.233:443
  117. 98.219.77.197:443
  118. 50.244.112.106:443
  119. 72.204.242.138:20
  120. 82.127.193.151:2222
  121. 65.100.247.6:2083
  122. 188.192.75.8:443
  123. 104.50.141.139:995
  124. 73.94.229.115:443
  125. 24.122.228.88:443
  126. 67.83.54.76:2222
  127. 72.29.181.77:2078
  128. 66.68.22.151:443
  129. 24.122.157.93:443
  130. 41.97.150.116:443
  131. 72.204.242.138:53
  132. 71.187.170.235:443
  133. 173.49.122.160:995
  134. 50.247.230.33:995
  135. 24.43.22.220:993
  136. 134.0.196.46:995
  137. 75.81.25.223:443
  138. 94.10.81.239:443
  139. 85.122.141.42:443
  140. 61.2.191.247:443
  141. 68.39.160.40:443
  142. 89.44.192.193:443
  143. 68.60.221.169:465
  144. 72.204.242.138:32100
  145. 72.204.242.138:6881
  146. 117.192.109.204:443
  147. 69.28.222.54:443
  148. 105.101.112.21:443
  149. 98.118.156.172:443
  150. 68.204.164.222:443
  151. 39.36.228.39:995
  152. 184.98.104.7:995
  153. 69.11.247.242:443
  154. 72.204.242.138:50003
  155. 5.107.208.94:2222
  156. 137.99.222.152:443
  157.  
  158. https://app.any.run/tasks/91441b12-4a15-413d-a73e-4438208ff6a3#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement