Advertisement
G0dR4p3

Gandcrab_IOC_23-04-2018

Apr 23rd, 2018
353
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.76 KB | None | 0 0
  1. #GandCrab #Ransomware #Trojan #Malware
  2. ------------------------------------------
  3. IOC's
  4. ------------------------------------------
  5. Main object- "mud.exe"
  6. url http://185.189.58.222/mud.exe
  7. sha256 ce9c9917b66815ec7e5009f8bfa19ef3d2dfc0cf66be0b4b99b9bebb244d6706
  8. sha1 d8eb074db4eabe9d48502b4a6ba8183c5337527c
  9. md5 a2bbae61bf0cf64b9d04b18cdd2a419d
  10. Dropped executable file
  11. sha256 C:\Users\admin\AppData\Roaming\Microsoft\gpcccd.exe 48adfc8b34392379507479bb2c218282afa8f03a2dd79f1eace1d763e86594cb
  12. DNS requests
  13. domain ransomware.bit
  14. domain ns1.corp-servers.ru
  15. domain ns2.corp-servers.ru
  16. domain ipv4bot.whatismyipaddress.com
  17. Connections
  18. ip 94.249.60.127
  19. ip 66.171.248.178
  20. ip 89.203.10.56
  21. HTTP/HTTPS requests
  22. url http://ransomware.bit/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement