Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Lokibot #Malware #Trojan
- ------------------------------
- 13-06-2018 IOC's
- ------------------------------
- Main object- "d311aaa5-2d76-421c-832d-09d60287467d"
- url http://prapro.tk/netty/Signed%20PI.exe
- sha256 293514d6e6722a41484db22dbd39170fc7a56046dc057e61e74d1a59c9db34f6
- sha1 6b8d3202a3deb9a205a961bee6a00d0b5db981ae
- md5 deab6d15bae0a844dbce0e7fc97d64a6
- Dropped executable file
- sha256 C:\Users\admin\AppData\Roaming\F63AAA\A71D80.exe 6df94b7fa33f1b87142adc39b3db0613fc520d9e7a5fd6a5301dd7f51f8d0386
- DNS requests
- domain prapro.tk
- Connections
- ip 217.146.91.100
- HTTP/HTTPS requests
- url http://prapro.tk/netty/Panel/five/fre.php
- -------------------------------
- UPDATED 14:37 - 13-06-2018
- Main object- "Swiftdetails.exe"
- url http://ideservesomeacollades.gq/Swiftdetails.exe
- sha256 c1094a857b95341db1134b678c35631b5fcc61387faf45f9a0dfcf348098716a
- sha1 97f6b8c9befbc10c26c4eaa55e7ac304f49edc89
- md5 4cce147dcb1eb6ae3354e830162564b5
- DNS requests
- domain eleletieleleparthard.ga
- Connections
- ip 103.63.2.227
- HTTP/HTTPS requests
- url http://eleletieleleparthard.ga/ari/Panel/fre.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement