Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- So Qakbot has been very quiet recently, signaling a possible distribution shift. Additionally, they've begun using a new crypter on some of their distro payloads. Currently, spx156 is on distro and an spx160 is on urlhaus.
- spx156:
- https://bazaar.abuse.ch/sample/d20b23f825b578b8eb266dce9bc9d89c1aaa38ea972924e59b599fe4fac4d3b9/ - unpacked loader
- https://bazaar.abuse.ch/sample/a9669005062b3c89146731a1fdd155f3902be2cfbb92a76b0173b61a35dd6516/ - extracted bot dll
- https://app.any.run/tasks/30520357-d3fd-4251-b0a4-437fa6dc5819
- spx160:
- https://urlhaus.abuse.ch/url/440920/ - if anyone has seen the other 4 or so urls, can you put them in urlhaus? (no need to worry about spx tag)
- https://bazaar.abuse.ch/sample/0dc7c1a0815b8e6ec06e7e09b94c6e3c18fc32a764c9943126e6161b7cb08cdd/ - unpacked loader
- https://bazaar.abuse.ch/sample/a9669005062b3c89146731a1fdd155f3902be2cfbb92a76b0173b61a35dd6516/ - extracted bot dll (same as spx156)
- https://app.any.run/tasks/920e99e6-3653-46e5-83c1-5a8a7e9a6b18
- IPs:
- 100.37.36.240:443
- 100.4.173.223:443
- 101.108.112.186:443
- 101.108.117.127:443
- 103.238.231.40:443
- 103.76.160.110:443
- 104.221.4.11:2222
- 108.27.217.44:443
- 108.28.179.42:995
- 108.30.125.94:443
- 108.46.145.30:443
- 108.5.32.113:443
- 117.218.208.239:443
- 117.248.60.13:443
- 118.168.238.196:443
- 12.5.37.3:995
- 120.57.69.162:443
- 130.25.130.19:2222
- 137.99.224.198:443
- 141.158.47.123:443
- 142.129.227.86:443
- 144.139.47.206:443
- 144.202.48.107:443
- 148.75.231.53:443
- 156.213.199.185:443
- 165.120.230.108:2222
- 166.62.180.194:2078
- 172.242.153.56:443
- 172.78.30.215:443
- 173.172.205.216:443
- 173.173.72.199:443
- 173.26.189.151:443
- 173.81.22.238:443
- 174.19.122.177:2222
- 175.111.128.234:443
- 175.211.225.118:443
- 176.205.255.97:443
- 178.193.38.188:2222
- 178.223.1.29:995
- 178.87.28.63:443
- 182.185.99.53:995
- 185.19.190.81:443
- 185.246.9.69:995
- 188.240.0.81:443
- 188.25.158.158:443
- 188.26.244.118:443
- 188.52.119.236:21
- 189.130.26.216:443
- 189.157.196.112:995
- 193.248.44.2:2222
- 195.162.106.93:2222
- 197.165.161.55:995
- 197.210.96.222:995
- 197.37.219.90:993
- 197.44.52.8:995
- 199.116.241.147:443
- 199.247.16.80:443
- 199.247.22.145:443
- 2.42.219.242:443
- 2.51.240.61:995
- 2.7.65.32:2222
- 2.89.116.206:995
- 203.106.195.67:443
- 203.198.96.186:443
- 203.45.65.20:443
- 206.51.202.106:50003
- 207.246.71.122:443
- 207.246.75.201:443
- 207.255.161.8:2078
- 207.255.161.8:465
- 207.255.161.8:993
- 207.255.161.8:995
- 209.137.209.163:995
- 209.140.8.178:443
- 209.182.122.217:443
- 211.24.72.253:443
- 213.120.109.73:2222
- 213.67.45.195:2222
- 216.163.4.132:443
- 216.201.162.158:443
- 217.162.149.212:443
- 217.165.115.0:990
- 217.165.164.57:2222
- 23.240.70.80:443
- 24.116.227.63:443
- 24.122.157.93:443
- 24.139.132.70:443
- 24.152.219.253:995
- 24.201.79.208:2078
- 24.27.82.216:2222
- 24.37.178.158:443
- 24.44.142.213:2222
- 24.46.40.189:2222
- 31.215.99.5:443
- 31.5.21.66:443
- 35.134.202.234:443
- 36.226.77.8:443
- 36.230.77.130:443
- 36.77.151.211:443
- 37.104.9.206:995
- 39.118.245.6:443
- 39.36.101.208:995
- 39.37.227.209:995
- 41.184.247.243:443
- 41.230.208.10:443
- 41.34.93.183:995
- 41.36.58.89:995
- 41.97.154.117:443
- 45.32.154.10:443
- 45.32.155.12:443
- 45.77.215.141:443
- 46.53.40.244:443
- 47.138.204.170:443
- 47.153.115.154:995
- 47.180.66.10:443
- 47.206.174.82:443
- 47.28.131.209:443
- 47.44.217.98:443
- 49.191.130.48:443
- 5.13.110.179:443
- 5.13.91.20:995
- 5.15.65.198:2222
- 5.193.155.181:2078
- 50.244.112.106:443
- 50.244.112.10:995
- 50.29.181.193:995
- 58.233.220.182:443
- 59.124.10.133:443
- 59.26.204.144:443
- 62.38.111.70:2222
- 63.155.9.62:995
- 64.130.165.255:443
- 65.131.64.201:995
- 65.131.73.141:995
- 65.96.36.157:443
- 66.215.32.224:443
- 66.222.88.126:995
- 66.26.160.37:443
- 66.30.92.147:443
- 67.165.206.193:993
- 67.170.137.8:443
- 67.209.195.198:443
- 67.246.16.250:995
- 67.6.3.51:443
- 68.174.15.223:443
- 68.190.152.98:443
- 68.204.164.222:443
- 68.39.160.40:443
- 68.4.137.211:443
- 68.60.221.169:465
- 69.26.23.143:2222
- 70.164.37.205:995
- 70.164.39.91:443
- 70.168.130.172:995
- 70.95.118.217:443
- 71.126.139.251:443
- 71.163.224.206:443
- 71.187.170.235:443
- 71.80.66.107:443
- 72.204.242.138:32100
- 72.204.242.138:32102
- 72.204.242.138:443
- 72.204.242.138:50001
- 72.204.242.138:53
- 72.204.242.138:990
- 72.66.47.70:443
- 73.104.218.229:0
- 73.214.248.17:995
- 73.228.1.246:443
- 73.232.165.200:995
- 73.78.149.206:443
- 74.56.167.31:443
- 75.110.250.89:995
- 75.136.40.155:443
- 75.182.214.87:443
- 75.183.171.155:995
- 75.87.161.32:995
- 76.111.128.194:443
- 76.19.219.126:995
- 77.27.173.8:995
- 77.27.174.49:995
- 77.31.122.1:995
- 78.100.229.44:61201
- 78.96.199.79:443
- 78.97.207.104:443
- 78.97.3.6:443
- 79.101.164.98:995
- 79.116.222.141:443
- 79.117.159.68:21
- 80.14.209.42:2222
- 80.195.103.146:2222
- 80.240.26.178:443
- 81.133.234.36:2222
- 82.79.67.68:443
- 83.110.6.64:2222
- 83.110.92.29:443
- 84.117.176.32:443
- 84.126.11.130:443
- 84.247.55.190:443
- 84.47.198.45:995
- 84.78.128.76:2222
- 85.122.111.225:443
- 86.122.251.89:2222
- 86.98.153.155:443
- 86.98.60.178:443
- 86.98.89.189:2222
- 86.98.89.40:2222
- 87.255.83.83:443
- 87.65.204.240:995
- 89.211.114.16:443
- 90.175.88.99:2222
- 92.59.35.196:2222
- 92.99.109.80:20
- 93.114.192.104:2222
- 93.151.180.170:61202
- 94.176.220.70:2222
- 94.205.171.126:995
- 94.59.241.189:2222
- 94.59.241.189:995
- 94.96.40.90:995
- 95.219.161.222:443
- 95.221.48.169:2222
- 95.76.185.240:443
- 95.77.144.238:443
- 95.77.223.148:443
- 95.77.235.132:0
- 96.18.240.158:443
- 96.19.117.140:443
- 96.20.108.17:2222
- 96.227.127.13:443
- 96.243.35.201:443
- 96.37.113.36:993
- 96.41.93.96:443
- 97.93.211.17:443
- 98.121.187.78:443
- 98.190.24.81:443
- 98.210.41.34:443
- 98.219.77.197:443
- 98.22.67.68:443
- 98.26.50.62:995
- 99.195.113.171:443
Add Comment
Please, Sign In to add comment