Advertisement
James_inthe_box

Gootkit IOC's

Feb 21st, 2018
1,444
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.85 KB | None | 0 0
  1. Sometimes js dropper
  2. C:\Users\<user>\AppData\Roaming\Microsoft\Internet Explorer\<characters>.inf
  3. C:\Users\<user>\AppData\Local\Temp\<digits>.bat
  4.  
  5. may check:
  6. C:\Users\<user>\AppData\Local\FileZilla\sitemanager.xml
  7. C:\Users\<users>\AppData\Local\GlobalSCAPE\CuteFTP\sm.dat
  8. HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
  9. HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
  10. HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander
  11. HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander
  12. HKEY_LOCAL_MACHINE\Software\FileZilla
  13.  
  14. sets:
  15. HKEY_CURRENT_USER\Software\AppDataLow\binaryImage32 <- many of these
  16.  
  17. mutex:
  18. ServiceEntryPointThread
  19.  
  20. network:
  21. Links like:
  22. /rpersist4/-327594751
  23. /rbody320
  24. /rpersist4/-1008320073
  25.  
  26. May start servers listening on 127.0.0.1:6443, 127.0.0.1:6080
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement