ExecuteMalware

2020-12-01 Guloader IOCs

Dec 2nd, 2020
4,107
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.59 KB | None | 0 0
  1. THREAT ATTRIBUTION: GULOADER
  2.  
  3. SUBJECTS OBSERVED
  4. RE: New Order
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. new order.xls
  10. d03c113f01b6adf3aa39f57da456caeb
  11.  
  12. PAYLOAD FILE HASHES
  13. sv.exe
  14. d248eb26ef65773b3af209f52224c360
  15.  
  16. GULOADER PAYLOAD DISTRIBUTION URLS FROM POWERSHELL/VB
  17. https://tinyurl.com/y5dsc4ag
  18. http://185.29.8.108/sv.exe
  19.  
  20. SECONDARY DOWNLOAD URL
  21. http://185.29.8.108/mg.bin
  22.  
  23. mg.bin
  24. 727836ec24ab95f5d67863435baa85e5
  25.  
  26. GULOADER OUTBOUND TRAFFIC
  27. 199.193.7.228:587
  28.  
  29. SUPPORTING EVIDENCE
  30. https://urlhaus.abuse.ch/url/882036/
  31. https://urlhaus.abuse.ch/url/882021/
Advertisement
Add Comment
Please, Sign In to add comment