MalwareQuinn

QakbotIOCs_Aug6

Aug 6th, 2020 (edited)
17,108
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.09 KB | None | 0 0
  1. Looks like Qakbot is back to using Emotet for malware distribution. New IP list released for botgroup "partner01", dropped by emotet.
  2.  
  3. Hash: ab273ccbc64f38250bf02605cb77de6c
  4.  
  5. IPs:
  6. 86.97.9.224:443
  7. 86.98.89.163:2222
  8. 173.163.115.89:2078
  9. 94.96.84.73:20
  10. 118.160.163.128:443
  11. 86.124.15.127:443
  12. 213.120.109.73:2222
  13. 197.210.96.222:995
  14. 217.165.112.13:995
  15. 2.51.240.61:995
  16. 41.225.13.128:8443
  17. 121.164.25.197:443
  18. 176.223.35.173:2222
  19. 87.65.204.240:995
  20. 75.110.250.89:995
  21. 217.165.110.181:443
  22. 101.108.14.229:443
  23. 66.30.92.147:443
  24. 122.57.75.113:443
  25. 31.215.110.235:2222
  26. 47.180.66.10:443
  27. 67.209.195.198:443
  28. 47.153.115.154:465
  29. 47.28.135.155:443
  30. 75.183.171.155:995
  31. 75.137.239.211:443
  32. 35.134.202.234:443
  33. 96.35.170.82:2078
  34. 90.175.88.99:2222
  35. 86.98.70.252:995
  36. 73.228.1.246:443
  37. 67.165.206.193:993
  38. 117.218.208.239:443
  39. 119.153.110.160:443
  40. 209.182.122.217:443
  41. 144.139.47.206:443
  42. 174.82.131.155:995
  43. 211.24.72.253:443
  44. 77.27.173.8:995
  45. 95.77.144.238:443
  46. 71.241.237.245:443
  47. 94.96.84.73:443
  48. 188.26.249.97:443
  49. 116.240.76.97:0
  50. 104.50.141.139:995
  51. 68.39.177.147:995
  52. 2.50.58.139:443
  53. 36.226.77.179:443
  54. 51.223.63.63:443
  55. 98.219.77.197:443
  56. 76.187.12.181:443
  57. 189.130.26.216:443
  58. 83.110.6.64:2222
  59. 47.39.76.74:443
  60. 71.182.142.63:443
  61. 134.228.24.29:443
  62. 98.110.231.63:443
  63. 79.118.27.41:443
  64. 84.117.176.32:443
  65. 68.46.142.48:995
  66. 47.153.115.154:443
  67. 61.1.203.13:443
  68. 65.96.36.157:443
  69. 203.106.195.67:443
  70. 172.116.85.178:443
  71. 151.73.120.201:443
  72. 199.247.22.145:443
  73. 86.98.66.175:2222
  74. 195.162.106.93:2222
  75. 47.153.115.154:993
  76. 103.76.160.110:443
  77. 59.98.98.136:443
  78. 172.242.156.50:443
  79. 64.130.165.255:443
  80. 24.110.96.149:443
  81. 151.244.169.28:443
  82. 70.164.37.205:995
  83. 67.246.16.250:995
  84. 86.120.237.47:2222
  85. 86.98.61.29:443
  86. 92.59.35.196:2222
  87. 51.241.113.55:443
  88. 89.211.179.56:61201
  89. 217.162.149.212:443
  90. 74.78.77.189:443
  91. 86.182.234.245:2222
  92. 144.202.48.107:443
  93. 95.76.185.240:443
  94. 93.151.180.170:61202
  95. 47.146.32.175:443
  96. 12.5.37.3:995
  97. 75.136.40.155:443
  98. 207.255.161.8:993
  99. 94.96.84.73:443
  100. 41.228.195.215:443
  101. 82.79.67.68:443
  102. 94.96.84.73:995
  103. 47.153.115.154:995
  104. 110.142.29.212:443
  105. 5.107.157.123:2222
  106. 31.167.7.42:443
  107. 93.113.177.152:443
  108. 103.238.231.40:443
  109. 59.26.204.144:443
  110. 207.246.71.122:443
  111. 80.240.26.178:443
  112. 199.247.16.80:443
  113. 207.255.161.8:995
  114. 72.209.191.27:443
  115. 65.60.228.130:443
  116. 71.74.12.34:443
  117. 70.121.182.223:2222
  118. 109.92.251.113:995
  119. 5.13.102.138:995
  120. 51.9.198.243:2222
  121. 77.159.149.74:443
  122. 212.33.114.169:443
  123. 174.30.168.163:2222
  124. 68.204.164.222:443
  125. 50.244.112.106:443
  126. 96.18.240.158:443
  127. 94.96.84.73:21
  128. 216.201.162.158:443
  129. 98.173.34.212:995
  130. 173.245.152.231:443
  131. 203.198.96.59:443
  132. 98.115.243.237:443
  133. 67.247.254.82:443
  134. 67.141.24.20:443
  135. 31.5.21.66:443
  136. 96.20.108.17:2222
  137. 83.110.92.29:443
  138. 115.21.224.117:443
  139. 47.153.115.154:990
  140. 63.155.9.141:995
  141. 94.52.160.116:443
  142. 217.165.15.243:443
  143. 188.15.173.34:995
  144. 173.173.72.199:443
  145. 81.133.234.36:2222
  146. 45.32.155.12:443
  147. 45.32.154.10:443
  148. 207.246.75.201:443
  149. 35.209.218.146:443
  150. 68.60.221.169:465
  151. 166.62.180.194:2078
  152. 68.116.98.118:443
  153. 78.96.199.79:443
  154. 217.165.164.57:2222
  155. 81.89.5.192:995
  156.  
  157. https://bazaar.abuse.ch/sample/c8a28d5f1a8e91d4ed9d5e35984aed80051f23efd13a158beeff3e0dfe4e4e5a/
Add Comment
Please, Sign In to add comment