Advertisement
Buky

IOC Globimposter : 28/10/2017

Dec 28th, 2017
321
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. ### Globimposter campaign 28/12/2017 ###
  2.  
  3. ## First Wave ##
  4. # Infos
  5. Tree: 7z archive > script
  6. Archive pattern: "CCE28122017_[0-9]{6}.7z"
  7. Script pattern: "CCE28122017_[0-9]{6}.vbs"
  8. Payload: https://www.virustotal.com/#/file/f8f07c01e2092c1cac889799a17a0f740c057375d105567fc2f31c946ff63232/community
  9.  
  10. # IOCs:
  11. hxxp://berkahbajamakmur.com/06YefeR?
  12. hxxp://slimthrive.net/06YefeR?
  13. hxxp://smartnewjerseyhomebuyers.com/06YefeR?
  14. hxxp://standardfederalproperties.com/06YefeR?
  15. hxxp://swarm-solutions.com/06YefeR?
  16. hxxp://weserve.world/06YefeR?
  17. hxxp://yourappyourway.com/06YefeR?
  18. hxxp://zeeshanasghar.website/06YefeR?
  19.  
  20. ## Second Wave ##
  21. #Infos:
  22. Tree: 7z archive > script
  23. Archive pattern: "(Scan|Document|PDF)_[0-9]{4,6}.7z"
  24. Script pattern: "(Scan|Copy|File)_[0-9]{8}.vbs"
  25. Payload: https://www.virustotal.com/#/file/eab3c6733e783f0a85608582f6c47238809306801ab8e80862b03497358de944/community
  26.  
  27. # IOCs:
  28. hxxp://9system.org/Mndv63?
  29. hxxp://amc-trans.ro/Mndv63?
  30. hxxp://baresiconstrucoes.com/Mndv63?
  31. hxxp://bluey.online/Mndv63?
  32. hxxp://cugaituoianthai.com/Mndv63?
  33. hxxp://desarrolloprueba.xyz/Mndv63?
  34. hxxp://iglesiaciudaddedios.com/Mndv63?
  35. hxxp://kooshesh-co.com/Mndv63?
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement