MalwareQuinn

QakbotIOC_Aug7

Aug 7th, 2020 (edited)
11,493
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.19 KB | None | 0 0
  1. Qakbot spun up spx150 around 9:19 UTC, with exe distro starting 13:33 UTC. H/T to @reecdeep for the find.
  2.  
  3. Sandbox: https://app.any.run/tasks/d708ea78-35ee-48d2-8134-39409909213f
  4.  
  5. VBS Name: TP1599119.vbs
  6.  
  7. Urls:
  8. http://40chorr.com/xlgkqwjt/8888888.png
  9. http://www.hospitaisipiranga.com.br/ewtxh/8888888.png
  10. http://tahanikhawaji.com/imbya/8888888.png
  11. http://whichworx.com/bmktzamm/8888888.png
  12.  
  13. IPs:
  14. 45.32.154.10:443
  15. 188.25.244.71:443
  16. 189.140.54.144:443
  17. 45.32.155.12:443
  18. 24.213.191.38:0
  19. 5.13.102.138:995
  20. 1.160.128.219:443
  21. 75.137.239.211:443
  22. 188.52.106.206:443
  23. 68.204.164.222:443
  24. 90.68.84.121:2222
  25. 68.14.210.246:22
  26. 86.153.98.2:2222
  27. 98.11.125.62:443
  28. 188.52.106.206:20
  29. 96.236.225.10:443
  30. 98.211.174.74:443
  31. 197.210.96.222:995
  32. 71.163.224.206:443
  33. 74.73.120.197:443
  34. 63.155.9.141:995
  35. 47.39.177.171:2222
  36. 96.20.108.17:2222
  37. 115.21.224.117:443
  38. 70.164.39.91:443
  39. 207.155.107.111:443
  40. 216.201.162.158:443
  41. 108.30.125.94:443
  42. 73.227.232.166:443
  43. 24.139.132.70:443
  44. 47.206.174.82:443
  45. 39.36.53.157:995
  46. 173.173.72.199:443
  47. 172.78.30.215:443
  48. 100.34.195.237:443
  49. 207.255.161.8:993
  50. 64.130.165.255:443
  51. 200.38.254.177:443
  52. 100.4.173.223:443
  53. 174.80.7.235:443
  54. 31.167.7.42:443
  55. 35.134.202.234:443
  56. 68.134.181.98:443
  57. 134.0.196.46:995
  58. 67.170.137.8:443
  59. 66.57.216.53:993
  60. 70.95.118.217:443
  61. 24.37.178.158:443
  62. 24.229.150.54:995
  63. 99.240.226.2:443
  64. 86.97.9.224:443
  65. 5.107.157.6:2222
  66. 186.6.197.11:443
  67. 67.247.254.82:443
  68. 47.44.217.98:443
  69. 96.232.163.27:443
  70. 110.142.29.212:443
  71. 86.97.146.204:2222
  72. 108.46.145.30:443
  73. 72.204.242.138:6881
  74. 117.218.208.239:443
  75. 86.182.234.245:2222
  76. 173.245.152.231:443
  77. 203.122.7.82:443
  78. 151.76.217.248:443
  79. 151.205.102.42:443
  80. 201.248.122.51:2078
  81. 187.163.101.137:995
  82. 156.213.224.213:993
  83. 117.241.54.103:443
  84. 89.247.216.229:443
  85. 199.247.22.145:443
  86. 74.129.24.163:443
  87. 78.97.3.6:443
  88. 173.163.115.89:2078
  89. 188.52.106.206:443
  90. 37.210.160.50:61201
  91. 193.248.44.2:2222
  92. 130.25.130.19:2222
  93. 141.158.47.123:443
  94. 173.22.120.11:2222
  95. 208.93.202.49:443
  96. 151.73.114.37:443
  97. 166.62.180.194:2078
  98. 188.26.98.35:443
  99. 103.206.112.234:443
  100. 74.75.237.11:443
  101. 189.183.35.120:995
  102. 24.99.180.247:443
  103. 75.136.40.155:443
  104. 71.182.142.63:443
  105. 68.4.137.211:443
  106. 182.185.13.1:995
  107. 72.142.106.198:465
  108. 98.243.187.85:443
  109. 81.133.234.36:2222
  110. 41.227.89.38:443
  111. 174.82.131.155:995
  112. 189.130.26.216:443
  113. 75.182.214.87:443
  114. 47.146.32.175:443
  115. 84.117.176.32:443
  116. 188.15.173.34:995
  117. 12.5.37.3:995
  118. 5.15.84.129:443
  119. 200.124.231.21:443
  120. 121.164.25.197:443
  121. 96.35.170.82:2078
  122. 165.228.200.94:443
  123. 103.238.231.40:443
  124. 70.126.76.75:443
  125. 31.5.116.167:443
  126. 66.208.105.6:443
  127. 201.216.216.245:443
  128. 98.219.77.197:443
  129. 75.110.250.89:995
  130. 2.88.50.153:995
  131. 70.164.37.205:995
  132. 148.75.231.53:443
  133. 217.165.110.181:443
  134. 104.235.63.89:443
  135. 2.90.70.49:995
  136. 66.30.92.147:443
  137. 47.138.204.170:443
  138. 98.26.50.62:995
  139. 217.165.112.13:995
  140. 94.59.241.189:995
  141. 98.4.227.199:443
  142. 24.44.142.213:2222
  143. 72.82.15.220:443
  144. 67.209.195.198:443
  145. 99.195.114.36:443
  146. 73.228.1.246:443
  147. 77.27.173.8:995
  148. 80.240.26.178:443
  149. 108.49.221.180:443
  150. 86.122.251.89:2222
  151. 199.247.16.80:443
  152. 84.247.55.190:443
  153. 76.111.128.194:443
  154. 149.71.51.2:443
  155. 72.185.47.86:995
  156. 94.52.160.116:443
  157. 5.15.100.152:443
  158. 73.23.194.75:443
  159. 72.214.55.195:995
  160. 68.184.45.73:443
  161. 76.187.12.181:443
  162. 83.110.226.145:443
  163. 67.165.206.193:993
  164.  
Add Comment
Please, Sign In to add comment